StudentManager icon indicating copy to clipboard operation
StudentManager copied to clipboard

There is sql injection at the login

Open zhaodie opened this issue 2 years ago • 0 comments

Build this project locally

There is a sql registration vulnerability in the login image It is found that there is a splicing of sql statements at the verification login image Vulnerability recurrence

Submit sql injection parameters

user=zzu'/**/and/**/extractvalue(1,concat(0x7e,(select/**/database()),0x7e))#&password=admin

image

zhaodie avatar Feb 13 '23 03:02 zhaodie