I want to use PHP/Mysql injection with a login example, my code is below.
I have tried with a username of anything\' -- and an empty password but it doe
anything\' --
If the value of username is:
$_POST['user'] = "1' OR 1 LIMIT 1; --";
Then the mysql query becomes:
select * from zend_adminlist where user_name = '1' OR 1 LIMIT 1; --' and password = '$pass'