appsecco / dvja

Damn Vulnerable Java (EE) Application
MIT License
130 stars 476 forks source link

SQL Injection: User Search does not return all records #17

Open cniddodi opened 3 years ago

cniddodi commented 3 years ago

SQL Injection: User Search under A1: Injection does not return all users for the query ' or '1'='1 It only returns one user record out of 3 user records.