1:靶场链接: https://hack.zkaq.cn/battle/target?id=485e58d0afa7e4f7https://hack.zkaq.cn/battle/target?id=485e58d0afa7e4f7https://hack.zkaq.cn/battle/target?id=485e58d0afa7e4f72:解题过程:(1):打开传送门,点击"点击查看新闻"发现url出现参数id=1,猜测为注入点。(2):判断字段个数: 注入代码:orderby3:页面显示异常