mysql injection login

Sale Price:$200.00 Original Price:$600.00
sale

SELECT * FROM users WHERE login='admin' AND password='1' OR '1'='1'; evaluates to SELECT * FROM users WHERE login='admin' AND TRUE. sinartogel login facebook login so it will select rows where login column value is admin It can be used to bypass the login It has a serious SQL injection vulnerability Its better to use Prepared Statement

Quantity:
Add To Cart