From 57d5b313b9a44acbd2f6c4b4e2bb4c132f645366 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fran=C3=A7ois=20Capon?= <46624375+FrancoisCapon@users.noreply.github.com> Date: Fri, 9 Feb 2024 10:17:38 +0100 Subject: [PATCH] Fix typo in SQLi blind case --- .../sqlinjection/documentation/SqlInjection_content13.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/resources/lessons/sqlinjection/documentation/SqlInjection_content13.adoc b/src/main/resources/lessons/sqlinjection/documentation/SqlInjection_content13.adoc index 749459d10..a43a5b484 100644 --- a/src/main/resources/lessons/sqlinjection/documentation/SqlInjection_content13.adoc +++ b/src/main/resources/lessons/sqlinjection/documentation/SqlInjection_content13.adoc @@ -34,7 +34,7 @@ This means an `orderExpression` can be a `selectExpression` which can be a funct a `case` statement we might be able to ask the database some questions, like: ---- -SELECT * FROM users ORDER BY (CASE WHEN (TRUE) THEN lastname ELSE firstname) +SELECT * FROM users ORDER BY (CASE WHEN (TRUE) THEN lastname ELSE firstname END) ---- So we can substitute any kind of boolean operation in the `when(....)` part. The statement will just work because