- sql injection in
index.vuln.js
line12
connection.query("SELECT * FROM ITEMS WHERE ID=" + req.params.id,(err, result) => {
res.json(result);
});
- sql injection in
index.vuln.js
line20
let query = {
sql : "SELECT * FROM ITEMS WHERE ID=" + req.params.id
}
connection.query(query,(err, result) => {
res.json(result);
});
- sql injection in
index.vuln.js
line24
connection.query({
sql : "SELECT * FROM ITEMS WHERE ID=" + req.params.id
},(err, result) => {
res.json(result);
});