完美时空某接口站sql注入
问题站点:
http://aapi.sd.wanmei.com/
看了下,各种接口
注射链接:
http://aapi.sd.wanmei.com/index.php/api/goods/getList?limit=10&offset=0&usage=
usage参数存在注射
http://aapi.sd.wanmei.com/index.php/api/goods/getTransactionList?goods_id=&limit=10&offset=0