原来sql:
String sql = " select count(*) from table where name ='' and password = ''";
输入namg:zhangsan 和 password:' or '1' ='1
登陆后sql:
String sql = " select count(*) from table where name ='zhangsan' and password = '' or '1' ='1'";
String sql = " select count(*) from table where name ='' and password = ''";
输入namg:zhangsan 和 password:' or '1' ='1
登陆后sql:
String sql = " select count(*) from table where name ='zhangsan' and password = '' or '1' ='1'";