Public website to demonstrate use of session hijacking and why input sanitization is needed.
Website: http://vader.infinityfree.me/
When we perform session hijacking via SQL injection attack, we can log in unauthorized and see the photo. The location of the photo can be extracted by its EXIF details.