Thread: sql injections
View Single Post
Go4Expert Member
20Aug2011,17:23  
Webdeveloper's Avatar
Hi,

You have not put any client side check to have both username and password as the mandatory field and in your query you are just checking the username and have not included password in the where clause.

Cheers,

~Maneet