我的 PHP/MySQL 代码中有如下几行:
...
$sqlquery = "SELECT price FROM products WHERE 1=1 AND id=".$_POST['id'];
...
... query is executed
...
echo $price;
作为测试/演示,如果我有一个表用户,我怎么能颠覆它来显示用户密码之类的东西:
id | username | password
------------------------
1 | abcde | qwerty
或者,我还能让系统显示什么?