News

Although a plain ''' is escaped, adding a bit to the beginning to make it a two-byte character makes it possible to skip the escape process. The SQL injection allowed the attacker to freely use ...