This application is a showcase for mysql injection
The situation is that company, Daniellas Industrial Bakery has hired a junior developer to create an active internal directory which allow employees to search for other employees. Unfortunatly since this person was a junior employee he made a few crucial mistakes. :) Have fun :)
app.py - This will serve a index.html which is a search bar which will allow a person to search for a name. results.html will host the results of the search. It will try and parse this into pretty boxes.
https://dev.mysql.com/doc/employee/en/employees-preface.html
mysql < employees.sql - Install employees