Found 'OR 1=1/* sql injection in my newsletter database

后端 未结 4 1435
北海茫月
北海茫月 2021-02-07 04:02

I found the following in the \"e-mail\" field of my newsletter subscriber database: \' OR 1=1/*

I know it\'s a SQL injection, but that\'s it. I\'ve goog

4条回答
  •  轻奢々
    轻奢々 (楼主)
    2021-02-07 04:48

    Its better if you use validation code to the users input for making it restricted to use symbols and part of code in your input form. If you embeed php in html code your php code have to become on the top to make sure that it is not ignored as comment if a hacker edit the page and add /* in your html code

提交回复
热议问题