$ 0 0 These are the basic exploitation steps for SQL Injection we follow for MySQL ... user manually with substring() and length(). {“user_id”=”xxxx AND length(database())=’1'#”}