路漫漫其修远兮,吾将上下而求索

导航

第三届NSCTFweb-easy_sql

111

 

 

<?php
  require("conf/config.php");
  if (isset($_REQUEST['id'])) { 
        $id = $_REQUEST['id'];
      if (preg_match("/\d.+?\D.+/is",$id)){
          die("Attack detected");
        }
        $query = "SELECT text from UserInfo WHERE id = " . $id. ";"; 
        $results = $conn->query($query);
        echo "学号:" . $id . ",成绩为: ".$results->fetch_assoc()['text'];
   }
?>

 

posted on 2020-07-05 17:48  爱在西元间  阅读(342)  评论(0编辑  收藏  举报