2.2汾£

ΰ汾Ҫ޸һҪSQLע⡣ѾװбԱϵͳֱظǵļеdbpath.aspļɡ޸ĹĬݿģǸļ޸Ϊݿ·ɡ


2.1汾£
ΰ汾£Աݡ
1.ҳӭٺԱЧ⡣index.aspǼɣ
2.ɾԱʺźݿȷ⡣admdel.aspǼɣ
3.ʾַʺź͹루ǵȫ⣬ʾַѾΪֻȨޣɾ޸Ļ500󣩣ʺ:jinjunhe 룺123456 ַhttp://www.45it.com/mianfeiliuyanban/index.asp?user=jinjunhe



2.05汾£

һ:ͳƴ벢˵

1Ŀ¼6.jsΪβͳƽűиΪԼͳƴ뼴
2/aitd/aitd06.js Ϊβ˺룬иΪԼĹ漴
3/aitd/aitd13.jsΪ԰ȫƯ룬иΪԼĹ漴

:վ͵ʼΪʾ״̬ڸأ

:ԤϢΪգҲн޸ģ

:Ա״̬ݿȡҪֶġ

20111211


45IT.COMûϵͳװ

-------------------------------------------
ϵͳ
-------------------------------------------
1õhttpd ApacheIISNginx ȣ
2֧ASP 
3ACCESSݿ

-------------------------------------------
ų̶ȣȫ
-------------------------------------------
װ
-------------------------------------------

οĲмɰİװ

1. ͨftpߣļϴ޸ģĬϼʹ

2. з: http://URL/

3. Աʺadmin 123456

4. ļdbpath.asp޸ݿ·ݷʷʽaspmdbȡ

5.ļadmin.aspʽhttp://URL/dmin.asp

6.ãaddsave45itcom.aspļ

7.ݿļbook.asp޸ACݿ⽫ļչΪmdbɡĬеʴ2

ףʹ죡


PS:ڹļaddsave45itcom.aspο
if ly="" or Len(Trim(ly)) > 500 then
errmsg=errmsg & " ʴĿѸİ棬뵽sos.45it.com\n"
end if
response.cookies("ly")=ly
if errmsg<>"" then
    Conn.Close
    Set conn = nothing
    Set rsc = nothing
    response.write("<script>alert('" & errmsg & "');history.go(-1)</script>")
    response.end
end if

˼ݴ500ֽڣʾ ʴĿѸİ棬뵽sos.45it.comʡύҳаƸʽдҲȡ
-------------------------------------------
* Ȩ: ӲӦ (45IT.COM Inc.)
* ܲ߻Ŀ: 45IT.COM
* Ŷ:45IT.COM
* Ȩ: ӲӦ (45IT.COM Inc.)
* ܲ߻Ŀ: 45IT.COM
* Ŷ:45IT.COM
* ٷվ: http://www.45it.com
*ʾַhttp://www.45it.com/mianfeiliuyanban/index.asp?user=jinjunhe
*ʹðhttp://www.45it.com/sos
