SQL Injection

SQL Injection

  1. $sql = "SELECT * FROM user WHERE username = '" . $_POST['username'] . "' AND password = '" . $_POST['password'] . "'";
  1. ?username=admin%27+--  (admin' --)
  1. ?username=?username=admin%27+OR+%27a%27%3D%27b  (admin' OR 'A'='A)