关于insert|update|delete注入中的tips

 2.updatexml()、extractvalue()、name_const()函数的使用

 3.I’ve noticed some variations in our payload. You can inject using these methods too. 

    ' or (payload) or ' 

    ' and (payload) and ' 

    ' or (payload) and ' 

    ' or (payload) and '=' 

    '* (payload) *' 

    ' or (payload) and ' 

    " – (payload) – "

原文地址:https://www.cnblogs.com/dongchi/p/4069090.html