Hotels_Server
Hotels_Server copied to clipboard
酒店预订系统后台管理系统
How can i translate to english
GET parameter 'password' appears to be 'MySQL
Poc http://114.116.xxx.xxx/Hotels_Server/controller/api/login.php?telephone=%3Cscript%3Ealert(/xss/)%3C/script%3E
In /view/hotelList.php data:image/s3,"s3://crabby-images/711aa/711aadbc631a69aae714a6ffa14a4c9d1adce8ea" alt="image" As you see, there are not any filtration in all ‘echo’s. Also in /controller/publishHotel.php , these are inserted into database without filtration data:image/s3,"s3://crabby-images/cc161/cc16129a2bec7ee4cbd7c61a9bfe185863192256" alt="image" After all, we can...
The application uses B64 encoding for storage of password Obscuring a password with a trivial encoding does not protect the password. data:image/s3,"s3://crabby-images/c3156/c31569bebf9ee3ae176bf0a9a4d36f02221d473b" alt="capture" https://cwe.mitre.org/data/definitions/261.html https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-password-cryptography-decoded
In controller/fetchpwd.php data:image/s3,"s3://crabby-images/f2bba/f2bbaa0a0e64bfa8bde2a6e26d062721f6660b73" alt="2019-01-19-225422_457x392_scrot" the parameter was added with a string "username=" ,passed to function find In the definition of function find,we can notice that though the author use PDO, he...