You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
我觉得上位师傅说的有点问题,当构造的payload为name=admin\#&password= or 1#时,此时对应的SQL语句是$query='SELECT * FROM users WHERE name=\''admin\'\' AND pass=\''or 1#'\';';,自己简化一下也就是$query='SELECT * FROM users WHERE name='admin AND pass=' or 1#',后面的AND pass是属于name那里的,上位师傅admin后面的'是不存在的
htmlentities()函数,单引号都被转义了,还注入个毛啊。。。。
The text was updated successfully, but these errors were encountered: