Hacker101 CTF-Micro-CMS v2

First, open the site to be this way

 Find a login box, there is injection vulnerability

 3. We can change the input usernames:

admin' or 1=1 --  

4. The error message Invalid Password , so we should also try to construct a password to login. After several attempts, I finally succeeded by using the payload, as follows:

admin' union select '123' as password -- 

And log in as the Administrator user using Pass 123.

 

 Back home, we can see a hyperlink, the hyperlink is linked to a private page, and showing the first signs.

 

Guess you like

Origin www.cnblogs.com/kuaile1314/p/12182771.html
v2