Podatkovne baze 1

« nazaj

Podatkovne baze 1 - vaje 14.12.2020

SQL injection

SELECT * FROM uporabnik
WHERE username = '{0}' AND password = '{1}';

Zlonamerni uporabnik vnese:

SELECT * FROM uporabnik
WHERE username = '' OR username = 'admin'; --' AND password = 'HAHA';