Sql injection
This commit is contained in:
parent
5dc2ac7922
commit
68c043f777
6
.idea/vcs.xml
generated
Normal file
6
.idea/vcs.xml
generated
Normal file
@ -0,0 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="VcsDirectoryMappings">
|
||||
<mapping directory="$PROJECT_DIR$" vcs="Git" />
|
||||
</component>
|
||||
</project>
|
@ -7,6 +7,7 @@ class Access
|
||||
{
|
||||
static function login($username, $password)
|
||||
{
|
||||
// ADORO L'SQL INJECTION ' OR '1'='1
|
||||
global $conn;
|
||||
$query = "SELECT * FROM users WHERE DESCRIZIONE = '$username' AND PASSWORD = '$password'";
|
||||
return $conn->query($query);
|
||||
|
@ -8,10 +8,16 @@ class Search
|
||||
static function searchByUsername($username)
|
||||
{
|
||||
global $conn;
|
||||
$query = "SELECT persone.* FROM users
|
||||
RIGHT JOIN persone ON persone.ID = users.ID_PERSONA
|
||||
WHERE users.DESCRIZIONE = '$username'";
|
||||
return $conn->query($query);
|
||||
$query = "SELECT persone.*
|
||||
FROM users
|
||||
RIGHT JOIN persone ON persone.ID = users.ID_PERSONA
|
||||
WHERE users.DESCRIZIONE = ?";
|
||||
|
||||
$stmt = $conn->prepare($query);
|
||||
$stmt->bind_param("s", $username);
|
||||
$stmt->execute();
|
||||
$result = $stmt->get_result();
|
||||
return $result;
|
||||
}
|
||||
|
||||
}
|
Loading…
x
Reference in New Issue
Block a user