select userid from demo_b2b_member where user = 'admin''You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''admin''' at line 1! t) O7 _+ Q& B& L$ d1 \2 `/ k
B9 w2 E& \/ w! w: ]4 c 复制代码 ( f9 r. q3 T: I9 I0 ^& ]6 i% O错误提示已经很明了了。我们看一下注入页面的代码(有删改):
$js_user = trim($_GET["js_user"]);
if($js_user){
$num = $db->num_rows("select userid from demo_b2b_member where user = '$js_user'");