SQL injection
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
Path URL: /php-sqlite-vms/?page=manage_visitor&id=1
Parameter: &id=[inject here]
This vulnerability allow attackers allow attackers to execute arbitrary SQL commands via the id parameters
When searching country with the incorrect condition 1' and '1'='2
, no results are returned:
And, when searching country with the incorrect condition 1' and '1'='1
, all results are returned: