The program allows an attacker to include characters that change the meaning of that SQL command.
这个程序允许攻击者包括可以修改SQL命令意义的字符。
Note that the name of the program is just argument number 0 in the command line values — don't trust the program name, since an attacker can change it.
注意,程序的名字只是命令行值的第0个参数——不要相信程序名,因为攻击者会改变它。
应用推荐