XVWA SQL Injection – Error Based/SQL Injection – Blind
0x00SQLInjection–ErrorBased手工审计一共两个文件,先看主页index.php,只有包含。接着再看home.php源代码,发现有两处传入参数j进行数据库操作,两处参数均无过滤。$item=isset($_POST['item'])?$_POST['item']:'';$search=isset($_POST['search'])?$_POST['search']:'';$i