Back
Syntax
Study
Editor
Mode:
HTML
CSS
JavaScript
PHP
Reset
Run »
HTML / CSS / JS
// Vulnerable $sql = "SELECT * FROM users WHERE email = '" . $_GET["email"] . "'"; // Safe: PDO prepared statement $stmt = $pdo->prepare("SELECT * FROM users WHERE email = :email AND active = 1"); $stmt->execute(["email" => $_GET["email"]]); $user = $stmt->fetch(); // Laravel Eloquent (parameterised automatically) $user = User::where("email", request("email"))->first();
Result
Open