fatso6996 wrote:i figured out how to do a sql injection but i need to know the url to inject.. i don't know what it should be. i tried user=*****.php but it didn't work (i used **** so others couldn't cheat to find out the admin name)
You're not putting it in the right place.




