, 'admin', 'dummy', 1 , :
' AND 1=0 UNION SELECT 'admin', 'dummy', admin FROM users WHERE admin = 1 AND '1'='1
:
SELECT username, password, admin FROM users
WHERE username='dummy' AND password='' AND 1=0 UNION SELECT 'admin', 'dummy', admin FROM users WHERE admin = 1 AND '1'='1'
SELECT , 1=0 . , SELECT , admin=1 , admin dummy .
You should use prepared statements and pass values as parameters when executing.
source
share