respectively.
If the original review loads with the "1=1"
URL and a blank or error page is returned from the "1=2" URL
and the returned page has not been created to alert the user the input is invalid
or in other words, has been caught by an input test script, the site is likely vulnerable to a SQL injection attack as the query will likely have passed through successfully in both cases. The hacker may proceed with this query string designed to reveal the version number of MySQL running on the server: