PortSwigger "SQL injection vulnerability in WHERE clause allowing retrieval of hidden data" Walkthrough
This is the first of Portswigger’s SQL injection labs. Before we get started, you’ll need Burp Suite installed (check out this blog post for setup instructions), and an Portswigger Academy account.