diff --git a/webgoat-container/src/main/java/org/owasp/webgoat/session/CreateDB.java b/webgoat-container/src/main/java/org/owasp/webgoat/session/CreateDB.java index 1805bd1618..d658b072ab 100644 --- a/webgoat-container/src/main/java/org/owasp/webgoat/session/CreateDB.java +++ b/webgoat-container/src/main/java/org/owasp/webgoat/session/CreateDB.java @@ -232,7 +232,7 @@ private void createUserAdminTable(Connection connection) throws SQLException { // Create the new table try { - String createTableStatement = "CREATE TABLE user_system_data (" + "userid varchar(5) not null primary key," + String createTableStatement = "CREATE TABLE user_system_data (" + "userid int not null primary key," + "user_name varchar(12)," + "password varchar(10)," + "cookie varchar(30)" + ")"; statement.executeUpdate(createTableStatement); } catch (SQLException e) { @@ -240,11 +240,11 @@ private void createUserAdminTable(Connection connection) throws SQLException { } // Populate - String insertData1 = "INSERT INTO user_system_data VALUES ('101','jsnow','passwd1', '')"; - String insertData2 = "INSERT INTO user_system_data VALUES ('102','jdoe','passwd2', '')"; - String insertData3 = "INSERT INTO user_system_data VALUES ('103','jplane','passwd3', '')"; - String insertData4 = "INSERT INTO user_system_data VALUES ('104','jeff','jeff', '')"; - String insertData5 = "INSERT INTO user_system_data VALUES ('105','dave','dave', '')"; + String insertData1 = "INSERT INTO user_system_data VALUES (101,'jsnow','passwd1', '')"; + String insertData2 = "INSERT INTO user_system_data VALUES (102,'jdoe','passwd2', '')"; + String insertData3 = "INSERT INTO user_system_data VALUES (103,'jplane','passwd3', '')"; + String insertData4 = "INSERT INTO user_system_data VALUES (104,'jeff','jeff', '')"; + String insertData5 = "INSERT INTO user_system_data VALUES (105,'dave','passW0rD', '')"; statement.executeUpdate(insertData1); statement.executeUpdate(insertData2); statement.executeUpdate(insertData3); diff --git a/webgoat-lessons/sql-injection/src/main/resources/lessonPlans/en/SqlInjection_content6a.adoc b/webgoat-lessons/sql-injection/src/main/resources/lessonPlans/en/SqlInjection_content6a.adoc index 17e5a279d5..fde2040a31 100644 --- a/webgoat-lessons/sql-injection/src/main/resources/lessonPlans/en/SqlInjection_content6a.adoc +++ b/webgoat-lessons/sql-injection/src/main/resources/lessonPlans/en/SqlInjection_content6a.adoc @@ -3,7 +3,7 @@ Lets try to exploit a join to another table. One of the tables in the WebGoat database is: ------------------------------------------------------- -CREATE TABLE user_system_data (userid varchar(5) not null primary key, +CREATE TABLE user_system_data (userid int not null primary key, user_name varchar(12), password varchar(10), cookie varchar(30));