less 4 GET - Error based - Double Quotes - String (基于错误的GET双引号字符型注入)

1、单引号  变成双引号

$id = '"' . $id . '"';
$sql="SELECT * FROM users WHERE id=($id) LIMIT 0,1";

猜你喜欢

转载自www.cnblogs.com/yilishazi/p/9020744.html