Advertisement
gwynplaine

diva_sqli

Nov 13th, 2020
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Java 0.63 KB | None | 0 0
  1. //code awal
  2.  
  3. public void search(View view) {
  4.         EditText srchtxt = (EditText) findViewById(R.id.ivi1search);
  5.         Cursor cr = null;
  6.         try {
  7.             cr = mDB.rawQuery("SELECT * FROM sqliuser WHERE user = '" + srchtxt.getText().toString() + "'", null);
  8.  
  9. //replace ' to nothing
  10. public void search(View view) {
  11.         EditText srchtxt = (EditText) findViewById(R.id.ivi1search);
  12.         Cursor cr = null;
  13.         try {
  14.             String myStr = srchtxt.getText().toString();
  15.             cr = mDB.rawQuery("SELECT * FROM sqliuser WHERE user = '" + myStr.replace('\'', '') + "'", null); //replace / hilangkan '
  16.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement