본문 바로가기
웹 해킹/sqli-labs-master

Less6-GET-Double Injection-Double Quotes-String

by sonysame 2019. 3. 4.

$id = '"'.$id.'"';

$sql="SELECT * FROM users WHERE id=$id LIMIT 0,1";


?id=" or "1"="1