从这个网页截图中,可以获取到以下关于漏洞的关键信息: 1. 漏洞名称:Music Gallery Site has a front-end SQL injection vulnerability 2. 受影响版本:Music Gallery Site - 1.0 3. 作者:Liuhaobin 4. 软件:https://www.sourcecodester.com/php/16073/music-gallery-site-using-php-and-mysql-database-free-source-code.html 5. 漏洞文件:/php-music/classes/Master.php?f=delete_category 6. 描述: - Music Gallery Site 1.0 受到在 /php-music/classes/Master.php? f=delete_category 中的攻击参数 id 的不受限制的 SQL 注入攻击的影响。 - 攻击者可以利用此漏洞直接获取敏感的服务器信息。 - 恶意攻击者可以利用此漏洞获取服务器数据库中的敏感信息。 7. 状态:CRITICAL 8. POC: - POST 请求示例: - 响应示例: ``` Error Error: XPATH syntax error: <?xml version="1.0" encoding="UTF-8"?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music/admin/xsl/styles.css" ?> <?xml-stylesheet type="text/xsl" href="http://localhost/php-music