Thread
:
sql injections
View Single Post
Webdeveloper
Go4Expert Member
20Aug2011,17:23
Hi,
You have not put any client side check to have both username and password as the mandatory field and in your query you are just checking the username and have not included password in the where clause.
Cheers,
~Maneet