Code review
String concatenation
$id = $_GET['id']; // User input taken directly from GET request
$query = "SELECT * FROM users WHERE id = '$id'";$username = $_GET['username'];
$password = $_GET['password'];
// Vulnerable SQL query using string concatenation (username and password)
$query = "SELECT * FROM users WHERE username = '" . $username . "' AND password = '" . $password . "'";$id = $_GET['id'];
$stmt = $mysqli->prepare("SELECT * FROM users WHERE id = ?");
$stmt->bind_param("i", $id);Narrowing the search
More regex payloads
Last updated