sql injection vulnerability in where clause allowing retrieval of hidden data

join shbcf.ru