当前位置:网站首页>[GWCTF 2019] I have a database 1
[GWCTF 2019] I have a database 1
2022-08-08 06:46:00 【Joker..】
It came in with a bunch of garbled characters. I checked the source code and found nothing when I captured the package. At this time, I can only use dirsearch
Go and scan it
You can see that there is a /phpmyadmin interface to visit
To get such an interface, the focus should be on the following one, generally this is to check the version loopholes
This is a phpmyadmin with such a vulnerability4.8.1 Remote File Inclusion Vulnerability (CVE-2018-12613)
Next, perform a vulnerability reproduction
payload: phpmyadmin/?target=db_sql.php%253f/../../../../../../../../etc/passwd
The execution is successful, since /etc/passwd can be read successfully, just try to read the flag directly
payload: phpmyadmin/?target=db_sql.php%253f/../../../../../../../../flag
Get it
(For the first time, just record it)
边栏推荐
- 聊一聊数据库中的锁
- 3.多线程两种实现方式的区别
- Detailed explanation of Scrapy crawler framework - comprehensive detailed explanation
- Refrigerator compressor market status research analysis and development prospect forecast
- List扩容机制
- Electronic payment market status quo of the study: 2022 volume is expected to increase to 314.1 billion yuan
- this指向问题
- 优势成长读书笔记
- 3. MATPLOTLIB data visualization analysis tool
- EOF指令在C语言中的作用
猜你喜欢
随机推荐
In 2022 China children's food market scale and development trend
改变this指向
MySQL----存储引擎
4.MySQL索引优化实战
玫瑰精油市场研究:目前市场产值超过23亿元,市场需求缺口约10%
Equipment industry research report: laser printer market present situation and development trend in the future
二叉树代码练习
四 、TF2.0中张量的数学运算
7.线程优先级
Detailed explanation of Scrapy crawler framework - comprehensive detailed explanation
三.Redis 的发布和订阅
MySQL基础
Mysql 事务
【熬夜整理近百份大厂面经】2022校招提前批面经总结分享(腾讯、字节、阿里、百度、京东等招聘信息+必考点+简历书写)
2022届暑期实习笔经面经总结,已拿微软微信offer
[WUSTCTF2020]朴实无华1
Instant Noodle Industry Survey: Expected to Reach $43.6 Billion in 2028
Electronic payment market status quo of the study: 2022 volume is expected to increase to 314.1 billion yuan
C语言初阶阶段的重难点知识总结
遥远的救世主