3. Injection
What is Injection?
Scenario 1
String query = "SELECT \* FROM accounts WHERE custID='" + request.getParameter("id") + "'";Scenario 2
Query HQLQuery = session.createQuery("FROM accounts WHERE custID='" + request.getParameter("id") + "'"); http://example.com/app/accountView?id=' or '1'='1Reference
Last updated
