´ó¼Ò¶ÔÍâ¹ÒÕâ¸ö´Ê¿Ï¶¨²»Ä°Éú°É£¿Õâ¿ÉÊÇÍæÍøÂçÓÎÏ·±Ø±¸¹¤¾ß°¡¡£ÏÖÔڵĺܶණÎ÷¶¼ÉÌÒµ»¯ÁË£¬Íâ¹ÒÒ²²»ÀýÍ⣬ºÃ²»ÈÝÒ×ÕÒµ½¸öºÃµãµÄÍâ¹Ò£¬µ«Êǵã»÷ÏÂÔصÄʱºò¾ÓȻ˵ҪÊÕ·Ñ£¬ÕæÊÇÆøËÀÈË¡£½ñÌìÎÒÃǾÍÒ»ÆðÀ´¿´Ò»¸öÍâ¹ÒÏÂÔØϵͳ´æÔڵĩ¶´¡£
»ªÏÄÍâ¹ÒÏÂÔØϵͳÊǹúÄÚʹÓñȽϹ㷺µÄÒ»¸öÍâ¹ÒÏÂÔØϵͳ£¬µ«ÊÇËü´æÔÚµÄÎÊÌâÈ´²»ÉÙ¡£ÎÒÃÇÏÈ¿´¿´SoftView.AspÎļþµÄ©¶´´úÂë¡£
if request.QueryString("SoftID")="" then
response.write "ÄúûÓÐÑ¡ÔñÏà¹ØÈí¼þ£¬Çë·µ»Ø"
response.end
end if
set rs=server.createobject("adodb.recordset")
sql="select Category.CateName,SubCate.SubCateName,SoftInfo.SoftName,SoftInfo.CateID,SoftInfo.SubID from SoftInfo,Category,SubCate where SoftInfo.CateID=Category.CateID and SoftInfo.SubID=SubCate.SubID and SoftInfo.SoftID="&request.QueryString("SoftID")
rs.open sql,conn,1,1
Õâ¶Î´úÂëÒ»¿ªÊ¼×öÁËÊÇ·ñΪ¿ÕµÄÑéÖ¤£¬µ«ÒòΪÊÇÖ±½ÓÅжÏrequest.QueryStringÕâÖÖÐÎʽ£¬ËùÒÔÐÎͬÐéÉè¡£ÔÙ¿´¿´ºóÃæ“SoftInfo.SoftID="&request.QueryString("SoftID")”Õâ¾ä´úÂ룬softidÃ÷ÏÔûÓйýÂ˾ͽø¿â²éѯÁË£¬Õâ¾Íµ¼ÖÂÁË×¢È멶´µÄ²úÉú£¡
ÓÉÓÚËüÊÇʹÓÃÁªºÏ²éѯµÄÐÎʽÀ´½ÓÊÕÊý¾Ý£¬ËùÒÔÎÒÃǾͲ»ÄÜʹÓÃunionÀ´Ö±½Ó±©ÃÜÂëÁË£¬»¹ÊǽÅ̤ʵµØµÄ²ÂÃÜÂë°É£¡Ëæ±ã´ò¿ªÒ»¸öʹÓÓ»ªÏÄÍâ¹ÒÏÂÔØϵͳ”µÄÍøÕ¾À´²âÊÔ£¨ÎÒÊÇÔÚ±¾»ú²âÊԵģ©£¬µã»÷Ò»¸öÍâ¹Ò£¬µÃµ½ÕâÑùµÄµØÖ·“http://127.0.0.1/lala/SoftView.Asp?SoftID=367”£¬OK£¬ÎÒÃÇÌá½»“and 1=1”ºÍ“and 1=2”¿´¿´£¬·Ö±ð·µ»ØÁËÕý³£ºÍ´íÎóÒ³Ã棬˵Ã÷×¢È멶´È·Êµ´æÔÚ¡£ÎÒÃÇÓÃNBSIÀ´½øÐÐ×¢Èë¼´¿É£¬°ÑµØÖ··Å½øNBSIÀÃÜÂëºÜ¿ì¾ÍÄܲ½â³öÀ´ÁË£¬Èçͼ1Ëùʾ¡£ÃÜÂëÊÇÓÃMD5¼ÓÃܵģ¬µ½www.cmd5.com»òwww.xmd5.com²éѯһÏ£¬µÃµ½ÆƽâºóµÄÃÜÂëÊÇ“wg00.com”¡£ÔÚµØÖ·À¸ºóÃæ¼ÓÉÏ“/admin/adminlogin.asp”£¬Óõõ½µÄÕ˺źÍÃÜÂë¼´¿ÉµÇ¼ºǫ́£¬Èçͼ2Ëùʾ¡£
ͼ1
ͼ2
ÏÖÔھͲîÄÃWebShellÁË¡£´ò¿ªºǫ́ÀïµÄ“Ìí¼ÓÎÄÕ”£¬ÆäÖÐÓиöÉÏ´«µÄµØ·½£¬ÎÒÃÇÉÏ´«Ò»¸ö¸ÄÁ˺ó׺µÄ³¬Å¨ËõDIYСÂíÉÏÈ¥£¬¼Ç¼ÏµØÖ·£¬È»ºóÔÙÔÚ“Êý¾Ý¿â¹ÜÀí”Àï°ÑÕâ¸öÎļþ±¸·Ý³ÉASP¸ñʽ¾Í¿ÉÒÔÁË£¬¾ßÌåÎҾͲ»¶à˵ÁË£¬²»ÊìϤµÄÅóÓÑ¿ÉÒÔ·¿´Ò»ÏÂÒÔÇ°µÄºÚ·À¡£
³ýÁËÕâ¸ö©¶´ÒÔÍ⣬SoftList.aspÎļþÒ²´æÔÚ©¶´£¬²¿·Ö´úÂëÈçÏ¡£
if request("CateID")<>"" and request("SubID")="" then
CateID="CateID="&request("CateID")"
sql="select CateName from Category where CateID="&request("CateID")
rs.open sql,conn,1,1
SoftDownName=trim(rs("CateName"))
CateName=trim(rs("CateName"))
rs.close
end if
ÆäÖеÄCateIDû×ö¹ýÂ˾ͽø¿â²éѯÁË£¬ÎÒÃÇÓÃÃ÷С×ÓµÄDOMAIN3.5½øÐÐ×¢Èë¿´¿´£¬È·¶¨Â©¶´È·Êµ´æÔÚ£¬Èçͼ3Ëùʾ¡£
ͼ3
ºÃÁË£¬¹ØÓÚ»ªÏÄÍâ¹ÒÏÂÔØϵͳ2.0µÄ©¶´¾Í·ÖÎöµ½ÕâÀïÁË£¬Èç¹û´ó¼ÒÓÐʲôÎÊÌâµÄ»°£¬¿ÉÒÔµ½ºÚ·ÀÂÛ̳À´ÕÒÎÒ£¬ÎÒµÄIDÊÇ“³ÏÃÔ¡£
Form£ººÚ°×Ç°Ïߣ¬×÷Õß:°¢³Ï