you must first create an account, and log in.
then you can send exploit
don't forget to change the action="" URL of this form
Username | you will use this username to login | ||
Password | you will use this password to login | ||
email doesn't have importance | |||
SQL Injection |
purpletech', niveau_num=4 WHERE num=2 /* <-- niveau_num is for admin access / num is the member id (default admin id is 2)
Now you are admin, logout and re-login with new username/password
There is another one injection :