I'm trying to use SQL Injection on my local server.
My Script is:
$query="SELECT * FROM tbl_admin WHERE admin_name ='".$uname."' AND admin_password ='".$pwd."'";
Now when I'm using admin' OR '1'='1'"; #
in name my query becomes
SELECT * FROM tbl_admin WHERE admin_name ='admin' OR '1'='1'"; #' AND admin_password ='*****'
When I check this query till 1 it is working fine. But not working in script.
I'm not getting quotes issue. Can anyone help me?