You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻求PHP中UPDATE查询的SQL注入漏洞利用方法(演示用)

Hey John, let's break this down step by step. Since you only shared a snippet of your code, I'll cover the most common reasons your UPDATE query might not be vulnerable, plus how to intentionally make it exploitable so you can demo SQL injection properly.

1. Why Your Current UPDATE Query Might Not Be Vulnerable

First, let's rule out the safe practices that could be blocking injection attempts:

  • Parameterized (Prepared) Statements: If you're using PDO or mysqli's prepared statements with bound parameters, user input is treated as raw data, not executable SQL. For example:
    $stmt = $pdo->prepare("UPDATE users SET email = ? WHERE id = ?");
    $stmt->execute([$_POST['email'], $_SESSION['user_id']]);
    
    This wraps input in safe, escaped contexts—so any ' DROP TABLE... you enter gets stored as part of the email string, not run as SQL.
  • Input Escaping: If you're using functions like mysqli_real_escape_string() or even addslashes() (though it's not ideal for all cases), special characters like single quotes get escaped (turned into \'). This breaks the structure of injection payloads, turning malicious input into harmless string data.
  • Non-User-Controlled WHERE Clause: If your UPDATE's WHERE uses a fixed value (like $_SESSION['user_id'] that users can't modify), even if the SET part had a flaw, executing DROP TABLE is tricky. Most PHP database drivers disable stacked queries (running multiple SQL statements at once) by default, so you can't just tack a DROP onto the end of an UPDATE.
2. How to Make Your UPDATE Query Exploitable for Demo

To intentionally create a vulnerable scenario, you need to remove those safeguards and set up conditions that let user input directly modify the SQL string. Here's how:

Example Vulnerable Code

This is purposefully unsafe code for demonstration only—never use this in production:

session_start();
require_once 'config.php';
error_reporting(E_ALL);

// Directly concatenate user input into SQL (no filtering/preprocessing)
$new_username = $_POST['username'];
// Let the user control the ID in the WHERE clause (instead of using a session value)
$target_user_id = $_POST['user_id'];

// Use mysqli_multi_query() to allow stacked queries (multiple SQL statements)
$query = "UPDATE users SET username = '$new_username' WHERE id = $target_user_id";
mysqli_multi_query($conn, $query);

Injecting DROP TABLE

With the code above, you can use these payloads to execute the drop command:

Payload for the Username Field

Enter this into the username input box:

' ; DROP TABLE demo_test_table; --

When concatenated, the SQL becomes:

UPDATE users SET username = '' ; DROP TABLE demo_test_table; --' WHERE id = 1
  • The ' closes the original string quote, ending the UPDATE's SET clause.
  • The ; terminates the UPDATE statement.
  • DROP TABLE demo_test_table; runs the delete command.
  • -- comments out the remaining SQL (' WHERE id = 1) to avoid syntax errors.

Payload for the User ID Field

Since the ID is a numeric value (no quotes around it), enter this into the user ID input:

1 ; DROP TABLE demo_test_table; --

The resulting SQL will be:

UPDATE users SET username = 'test' WHERE id = 1 ; DROP TABLE demo_test_table; --
3. Critical Demo Notes
  • Test Locally Only: Use a local environment like XAMPP or WAMP—never experiment with this on a live server.
  • Enable Stacked Queries: For mysqli, use mysqli_multi_query() instead of mysqli_query() (the latter only runs the first statement). For PDO, you'll need to enable multi-statements in your DSN: new PDO("mysql:host=localhost;dbname=test", "user", "pass", [PDO::MYSQL_ATTR_MULTI_STATEMENTS => true]).
  • Check Database Privileges: Make sure your database user has permission to drop tables—otherwise the injection will fail with a permission error.
  • Use Error Reporting: Your existing error_reporting(E_ALL); will help you debug payloads by showing SQL syntax errors if something goes wrong.

内容的提问来源于stack exchange,提问作者John

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:38:15