PHPize Online / SQLize Online  /  SQLtest Online

A A A
Share      Blog   Popular
Copy Format Clear
CREATE TABLE users (`username` varchar(20), `id` int, `password` varchar(20)) ; INSERT INTO users (username, id, password) VALUES ("victim", 1, "passkey");
Copy Clear
Copy Format Clear
<?php $username = "victdim"; $id = "1)||1=1#"; // $id = "1)||(@@version >= 8 )||(1=1"; $password = "passkdey"; $query = "SELECT * FROM users WHERE (username='$username' and id=$id) and password='$password'"; echo $query; echo "\n\n"; $result = $mysqli->query($query); while($row = mysqli_fetch_array($result)) { print_r($row); }
Show:  
Copy Clear