mission 7
this is as far as i have gotten:
got the admin details (but have to use that last)
attempted SQL injection on access.php, But im guessing this is the right track, but im getting syntax errors:
You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'SELECT * FROM XXXXX WHERE id=1' at line 1
any ideas???
yeah, i've been trying to guess a password. What i've seen with the teachers is that Ms. Jennifer Smith has an id of 20 and Ms. Yoshi James has an id of 1, yet there are only 16 teachers in the list. I've managed to find one that isn't a real id so far, and that's id=6. It's probably nothing, but you never know….
I was also able to generate the error you got Mr_Cheese, from the teacherinfo.php url.