上传者: 38621565
|
上传时间: 2021-12-17 22:22:30
|
文件大小: 37KB
|
文件类型: -
先看看那种容易被注入的SQL
id = 11001
sql =
SELECT
id,
name,
age
FROM
student
WHERE
id = +id+
cursor = connection.cursor()
try:
cursor.execute(sql)
result = cursor.fetchall()
for result1 in result:
// 代码块