Guest User

Untitled

a guest
Mar 4th, 2018
84
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 0.82 KB | None | 0 0
  1.   $query = DB::query(Database::UPDATE,'UPDATE user SET session = :session WHERE username = :username AND password = :password');
  2.         $query->parameters(array(
  3.             ':session'=>  Session::instance()->id(),
  4.             ':username'=>Database::instance()->quote('BlackScorp/;SELECT * FROM user;--'),
  5.             //':username'=>'BlackScorp/;SELECT * FROM user;--',
  6.             ':password' => 'mycoolpassword'
  7.         ));
  8.         $query->execute();
  9.        
  10.         echo $query->__toString();
  11.  
  12. //echo gives UPDATE user SET session = 'siav2s8oc5sk0fd7bdh27to4f5' WHERE username = '\'BlackScorp/;SELECT * FROM user;--\'' AND password = 'mycoolpassword'  if i quote it
  13.  
  14. //without quote UPDATE user SET session = 'siav2s8oc5sk0fd7bdh27to4f5' WHERE username = 'BlackScorp/;SELECT * FROM user;--' AND password = 'mycoolpassword'
Add Comment
Please, Sign In to add comment