A question of SQL statement injected by SQL


SQL:
select * from post where id = "10";

:
10" union select id,username,salt,password,5 from user where id="2

:
select * from post where id = "10\" union select id,username,salt,password,5 from user where id=\"2"

I don"t know why I can query the data.

clipboard.png

Mar.15,2021

your id MYSQL setting is numeric, but you are querying character types. At this point, MYSQL does an implicit conversion and does not use indexes. Where characters are converted to numbers:

  1. start processing from the left
  2. The
  3. string begins with a non-numeric number and is converted to the number 0
  4. The
  5. string begins with a number and is directly intercepted to a non-numeric position. Which is in your question: 10
Implicit conversion occurs during the execution of

sql statement

MySQL Query : SELECT * FROM `codeshelper`.`v9_news` WHERE status=99 AND catid='6' ORDER BY rand() LIMIT 5
MySQL Error : Disk full (/tmp/#sql-temptable-64f5-1beb4cb-31a52.MAI); waiting for someone to free some space... (errno: 28 "No space left on device")
MySQL Errno : 1021
Message : Disk full (/tmp/#sql-temptable-64f5-1beb4cb-31a52.MAI); waiting for someone to free some space... (errno: 28 "No space left on device")
Need Help?