14-12-2011
$user = $_POST['user']; $pass = $_POST['password']; $sql = "select * from table1 where user ='$pass' and pass='$pass'; //on fait un petit test $user = "dean"; $pass == "mon pass" ; //la requête devient select * from table1 where user ='dean' and pass= 'monpass' //on fait un autre test $user = "dean"; $pass == " ' or 1=1 " ; //la requête devient select * from table1 where user ='dean' and pass= ' ' or 1=1
Aiiiie

Injection SQL :code à risque 1
-injection SQL php
>> Voir tous les tutoriels catégories: injection SQL, php