当前位置:网站首页>SQL Injection (AJAX/JSON/jQuery)
SQL Injection (AJAX/JSON/jQuery)
2022-07-03 13:45:00 【this is hhhhp】
1.AJAX/JSON/jQuery
(1)AJAX
Through a small amount of data exchange with the server in the background ,AJAX Asynchronous update of web pages . This means that you can load the entire page without reloading it , Update a part of the web page in real time .
(2)JSON
JSON (JavaScript Object Notation) Is a lightweight data exchange format .
Is a data format .
(3)jQuery
jQuery It's a JavaScript library , Use jQuery Not only will it take a lot of JavaScript Code to achieve the function reduced to a few lines of code , It also provides enough high-speed performance , It's a skill that every website developer should master .
2. Inject
Let's grab a bag first :
Enter... In the input box i

Bag caught :

first line ,title=i, Change to ' have a look :
sql Wrong report , guess sql The statement is as follows :
select * from Table name where Title like '%". User input ."%'

So it can be constructed like this sql sentence :
select * from Table name where Title like '%"' or '"%
The inquiry is correct , All the movies are

On this basis, inject :
0' union select 1,2,3,4,5,6,7 'obtain 2,3,4,5, altogether 4 Displayable bits

Blast storage :
0' union select 1,database(),3,4,5,6,7 ' 
Just behind GET/Search About the same .
边栏推荐
- windos 创建cordova 提示 因为在此系统上禁止运行脚本
- MySQL functions and related cases and exercises
- Spark实战1:单节点本地模式搭建Spark运行环境
- 服务器硬盘冷迁移后网卡无法启动问题
- JSON serialization case summary
- 8 Queen question
- Comprehensive evaluation of double chain notes remnote: fast input, PDF reading, interval repetition / memory
- Kivy tutorial how to load kV file design interface by string (tutorial includes source code)
- Leetcode-1175.Prime Arrangements
- AI scores 81 in high scores. Netizens: AI model can't avoid "internal examination"!
猜你喜欢

Complete deep neural network CNN training with tensorflow to complete picture recognition case 2

PowerPoint 教程,如何在 PowerPoint 中将演示文稿另存为视频?

Kivy教程之 盒子布局 BoxLayout将子项排列在垂直或水平框中(教程含源码)

Several common optimization methods matlab principle and depth analysis

Logseq evaluation: advantages, disadvantages, evaluation, learning tutorial

全面发展数字经济主航道 和数集团积极推动UTONMOS数藏市场

Smbms project

Internet of things completion -- (stm32f407 connects to cloud platform detection data)

The difference between stratifiedkfold (classification) and kfold (regression)
![[sort] bucket sort](/img/52/95514b5a70cea75821883e016d8adf.jpg)
[sort] bucket sort
随机推荐
R语言使用data函数获取当前R环境可用的示例数据集:获取datasets包中的所有示例数据集、获取所有包的数据集、获取特定包的数据集
掌握Cypress命令行选项,是真正掌握Cypress的基础
Shell timing script, starting from 0, CSV format data is regularly imported into PostgreSQL database shell script example
挡不住了,国产芯片再度突进,部分环节已进到4nm
Heap structure and heap sort heapify
编程内功之编程语言众多的原因
rxjs Observable filter Operator 的实现原理介绍
Resolved (error in viewing data information in machine learning) attributeerror: target_ names
(first) the most complete way to become God of Flink SQL in history (full text 180000 words, 138 cases, 42 pictures)
Mysql database basic operation - regular expression
Mycms we media mall v3.4.1 release, user manual update
Flink SQL knows why (17): Zeppelin, a sharp tool for developing Flink SQL
今日睡眠质量记录77分
AI scores 81 in high scores. Netizens: AI model can't avoid "internal examination"!
又一个行业被中国芯片打破空白,难怪美国模拟芯片龙头降价抛售了
NFT new opportunity, multimedia NFT aggregation platform okaleido will be launched soon
Students who do not understand the code can also send their own token, which is easy to learn BSC
KEIL5出现中文字体乱码的解决方法
R language uses the data function to obtain the sample datasets available in the current R environment: obtain all the sample datasets in the datasets package, obtain the datasets of all packages, and
Detailed explanation of multithreading
