• 关于xor在注入中的运用,XOR少有人提及。跟人讲的嘴巴痛。。
  • Author_booksave.asp


    b_id=request.form("list_bookid") //162行
    c_id=request.form("list_cookid") //163行

    sql4="select top 1 * from [list_view] where list_cookid="&c_id&" order by view_showid desc"  //173行注入

    sql="select list_cookname from [list_cook] where list_cookid="&c_id //237行,注入

    sql="selec...