busy-arm-75131
03/16/2023, 11:57 AMbusy-arm-75131
03/16/2023, 11:57 AMpowerful-noon-83514
03/16/2023, 11:57 AMgentle-london-6993
03/16/2023, 11:57 AMprehistoric-airport-78826
03/16/2023, 11:57 AMable-spring-37783
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMable-spring-37783
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMbusy-arm-75131
03/16/2023, 11:58 AMsql
SELECT * FROM acc WHERE name = '%s';
with your answer it would just do this:
sql
`SELECT * FROM acc WHERE name = 'DROP TABLE acc';
which means you just querying a string, not injecting stuffgentle-london-6993
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMprehistoric-airport-78826
03/16/2023, 11:58 AMgentle-london-6993
03/16/2023, 11:59 AMprehistoric-airport-78826
03/16/2023, 11:59 AMprehistoric-airport-78826
03/16/2023, 11:59 AMprehistoric-airport-78826
03/16/2023, 11:59 AMpowerful-noon-83514
03/16/2023, 11:59 AMbig-notebook-78712
03/16/2023, 12:00 PMgentle-london-6993
03/16/2023, 12:00 PMbusy-arm-75131
03/16/2023, 12:00 PMprehistoric-airport-78826
03/16/2023, 12:00 PMbrave-energy-42672
03/16/2023, 12:00 PMpowerful-noon-83514
03/16/2023, 12:00 PMgentle-london-6993
03/16/2023, 12:00 PMgentle-london-6993
03/16/2023, 12:01 PMbusy-arm-75131
03/16/2023, 12:01 PM