myq注入 py操作数据库
mysq注入 就是利用mysql 语法 使其 查询条件永远为真 import pymysql conn = pymysql.connect(host='127.0.0.1', user='root', password="123", database='day43') cur = conn.cursor() user = "akhksh' or 1=1 ;-- " password = '*******' sql = "select * from userinfo where username = %s and password =%s;" print(sql) cur.execute(sql,(user,password)) ret = cur.fetchone() print(ret) cur.close() conn.close() 查询 # 光标会记录位置 取得那就会记录此时的位置 import pymysql conn = pymysql.connect( host='127.0.0.1', port=3306, user='root', password='', database='daycs', charset='utf8', ) cursor = conn.cursor(pymysql.cursors.DictCursor) sql = "select * from