When I post for the first time, I will give you a thought of yesterday.
Tested CMS: site building star.
Because it is easier for SEO to do pseudo-static operations, many CMS also have pseudo-static operations. However, pseudo-static is mainly used to hide the passed parameter name. It is only a method for URL rewriting. Since parameter input is acceptable, injection cannot be prevented.
We can see that there are many pseudo-static injection methods on the Internet.
Eg.
Http://www.XXX.com/play/Diablo' and 1w.'1.html and http://www.XXX.com/play/Diablo' and 1w.'2.html to judge
That's why I didn't use this method this time.
I downloaded a website builder. After the local build, the following instances are available after the test.
I don't know if this is correct. Please give me some advice.
Http://www.kinhan.cc/mod_article-fullist-caa_id-19.html
Let me try the injection like this:
No. no results have been returned after several battles.
Then I changed my posture. After the local test, I tried the following link.
Http://www.kinhan.cc/index.php? _... Ullist & caa_id = 1
The two are actually the same. Let's try dropping SQLMAP.
Here is just an idea. Because some CMS can be downloaded. So it can be used. Test it locally.