开发者官网  https://mambo-developer.org

缺陷类别*SQL injection Vulnerability*

测试示例-

The "zorder" parameter was not properly sanitized upon submission to

the administrator/index2.php url, which allows attacker to conduct

SQL Injection attack.

https://www.2cto.com /mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder=