Merge pull request #214 from Reelix/patch-1
Added alternate quote variation
This commit is contained in:
commit
8fb43e1c37
@ -201,7 +201,9 @@ $q = '/usuarios/usuario[cuenta="' . $_POST['user'] . '" and passwd="' . $_POST['
|
||||
|
||||
```text
|
||||
' or '1'='1
|
||||
" or "1"="1
|
||||
' or ''='
|
||||
" or ""="
|
||||
string(//user[name/text()='' or '1'='1' and password/text()='' or '1'='1']/account/text())
|
||||
|
||||
Select account
|
||||
|
Loading…
Reference in New Issue
Block a user