将SQL查询注入PHP代码

时间:2015-03-18 15:37:32

标签: php mysql sql

如何将以下内容注入PHP?该页面不会加载以下代码。



                    $result = mysql_query("INSERT INTO phpn_banned_ip (ip_address, reason)
SELECT host_addr, "Spam" FROM phpn_session
WHERE guest='1';");




1 个答案:

答案 0 :(得分:0)

$result = mysql_query("INSERT INTO phpn_banned_ip (ip_address, reason)
SELECT host_addr, "Spam" FROM phpn_session
WHERE guest='1';");

更改为:

$result = mysql_query("INSERT INTO phpn_banned_ip (ip_address, reason)
SELECT host_addr, 'Spam' FROM phpn_session
WHERE guest='1';");

(更改为围绕垃圾邮件的单引号)