A blind SQL injection vulnerability.
The web application was full of blindies, such as:login.asp?username=' OR '1'='1&password=d0ngz
6👍 1👎