T

You might also like

You are on page 1of 7

WHERE Username = 'x' Or 1=1 --'' AND Passwd

Cách chống sql injection:

Dùng parameter, chuyền tham số vào

==> WHERE Username = @username AND Passwd = @Passwd

---Tuyệt đối không nối chuỗi

<!-- Admin comment -->

@foreach($comment_ad as $cmt)

<div class="media">

<!-- first comment -->

<div class="media-heading">

<span class="label label-info">{{ $cmt->name }}</span> {{ $cmt->date }}

</div>

<div class="panel-collapse collapse in" id="collapseOne">

<div class="media-left">

<div class="vote-wrap">

<div class="save-post">

<a href="#"><span class="glyphicon glyphicon-star" aria-label="Save"></span></a>

</div>

</div>

<!-- vote-wrap -->

</div>

<!-- media-left -->


<div class="media-body">

<p>{{ $cmt->content }}</p>

<div class="comment-meta">

<span><a href="#">delete</a></span>

<span>

<a class="" role="button" data-toggle="collapse" href="#{{ $cmt->id }}" aria-


expanded="false" aria-controls="collapseExample">reply</a>

</span>

<div class="collapse" id="{{ $cmt->id }}">

<form>

<div class="form-group">

<label for="comment">Your Comment</label>

<textarea name="comment" class="form-control" rows="3"></textarea>

</div>

<button type="submit" class="btn btn-default">Send</button>

</form>

</div>

</div>

<!-- comment-meta -->

<div class="media">

<!-- answer to the first comment -->

<div class="media-heading">

<span class="label label-info">12314</span> vertu 12 sat once yazmis

</div>

<div class="panel-collapse collapse in" id="collapseTwo">


<div class="media-left">

<div class="vote-wrap">

<div class="save-post">

<a href="#"><span class="glyphicon glyphicon-star" aria-label="Save"></span></a>

</div>

</div>

<!-- vote-wrap -->

</div>

<!-- media-left -->

<div class="media-body">

<p>yazmayın artık amk, görmeyeyim sol framede. insan bi meraklanıyor, ümitleniyor. sonra
yine özlem dolu yazıları görüp hayal kırıklığıyla okuyorum.</p>

<div class="comment-meta">

<span>

<a class="" role="button" data-toggle="collapse" href="#replyCommentThree" aria-


expanded="false" aria-controls="collapseExample">reply</a>

</span>

<div class="collapse" id="replyCommentThree">

<form>

<div class="form-group">

<label for="comment">Your Comment</label>

<textarea name="comment" class="form-control" rows="3"></textarea>

</div>

<button type="submit" class="btn btn-default">Send</button>

</form>

</div>
</div>

<!-- comment-meta -->

</div>

</div>

<!-- comments -->

</div>

</div>

@endforeach

<!-- Customer comment -->

@foreach($comment_cus as $cmt)

<div class="media">

<!-- first comment -->

<div class="media-heading">

<span class="label label-info">{{ $cmt->name }}</span> {{ $cmt->date }}

</div>

<div class="panel-collapse collapse in" id="collapseOne">

<div class="media-left">

<div class="vote-wrap">

<div class="save-post">

<a href="#"><span class="glyphicon glyphicon-star" aria-label="Save"></span></a>

</div>

</div>

<!-- vote-wrap -->


</div>

<!-- media-left -->

<div class="media-body">

<p>{{ $cmt->content }}</p>

<div class="comment-meta">

<span><a href="#">delete</a></span>

<span>

<a class="" role="button" data-toggle="collapse" href="#{{ $cmt->id }}" aria-


expanded="false" aria-controls="collapseExample">reply</a>

</span>

<div class="collapse" id="{{ $cmt->id }}">

<form>

<div class="form-group">

<label for="comment">Your Comment</label>

<textarea name="comment" class="form-control" rows="3"></textarea>

</div>

<button type="submit" class="btn btn-default">Send</button>

</form>

</div>

</div>

<!-- comment-meta -->

<div class="media">

<!-- answer to the first comment -->

<div class="media-heading">

<span class="label label-info">12314</span> vertu 12 sat once yazmis


</div>

<div class="panel-collapse collapse in" id="collapseTwo">

<div class="media-left">

<div class="vote-wrap">

<div class="save-post">

<a href="#"><span class="glyphicon glyphicon-star" aria-label="Save"></span></a>

</div>

</div>

<!-- vote-wrap -->

</div>

<!-- media-left -->

<div class="media-body">

<p>yazmayın artık amk, görmeyeyim sol framede. insan bi meraklanıyor, ümitleniyor. sonra
yine özlem dolu yazıları görüp hayal kırıklığıyla okuyorum.</p>

<div class="comment-meta">

<span><a href="#">delete</a></span>

<span>

<a class="" role="button" data-toggle="collapse" href="#replyCommentThree" aria-


expanded="false" aria-controls="collapseExample">reply</a>

</span>

<div class="collapse" id="replyCommentThree">

<form>

<div class="form-group">

<label for="comment">Your Comment</label>

<textarea name="comment" class="form-control" rows="3"></textarea>


</div>

<button type="submit" class="btn btn-default">Send</button>

</form>

</div>

</div>

<!-- comment-meta -->

</div>

</div>

<!-- comments -->

</div>

</div>

@endforeach

You might also like