You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地网站SQL注入尝试失败,mysqli_fetch_assoc报错求助

Fixing the mysqli_fetch_assoc() Boolean Parameter Error in Your SQL Injection Attempt

Hey there! Let's break down why you're hitting that error and get your SQL injection attempt working properly.

First off, that error message tells you your SQL query failed to execute successfully. When mysqli_fetch_assoc() expects a mysqli_result object but gets a boolean, it means mysqli_query() returned false—the database couldn't run your query because of a syntax issue.

Why Your Current Injection Isn't Working

Let's assume your original PHP query looks something like this (based on your code snippet):

$sql = "SELECT * FROM product WHERE product_name LIKE '%$search_value%'";

When you pass ';-- as the search value, the resulting SQL becomes:

SELECT * FROM product WHERE product_name LIKE '%';--%'

See the problem? The %' closes the initial quote, ; ends the current statement, and -- starts a comment—but the leftover %' at the end is invalid syntax. The database throws an error, so the query returns false instead of a result set, hence the mysqli_fetch_assoc() error.

A Working Injection to Get All Products

To pull all records from the product table, you need to craft an injection that makes the WHERE condition always evaluate to true. Try using ' OR 1=1;-- as your search value.

The resulting SQL will be:

SELECT * FROM product WHERE product_name LIKE '%' OR 1=1;--%'

Here's what happens:

  • OR 1=1 ensures the WHERE clause is always true, so every row is returned
  • -- comments out the trailing %', eliminating the syntax error

Debugging Tip for Future Attempts

To quickly see why your SQL is failing, add an error check before processing the result set:

$result = mysqli_query($conn, $sql);
if (!$result) {
    die("SQL Execution Error: " . mysqli_error($conn));
}

// Now process the result
while ($row = mysqli_fetch_assoc($result)) {
    // Handle your product data here
}

This will print the exact database error message, making it easy to tweak your injection syntax.


内容的提问来源于stack exchange,提问作者Usman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:43:17