=======
- IDEA
- Burp
- WebGoat v8.0.0.M21
org.owasp.webgoat.plugin.introduction.SqlInjectionLesson5a.java
数据污染流如下,POST参数数据未经过处理直接进入函数,最终进入query语句,导致sql注入。
String query= "SELECT * FROM user_data WHERE last_name =? ;
PreparedStatement preState = conn.prepareStatement(query);
preState.setString(1, accountName);
ResultSet rs = preState.executeQuery();