Inurl -.com.my Index.php Id -
Never trust user input. If id is supposed to be a number, cast it to an integer:
$id = (int) $_GET['id'];
/index.php?id=123' WAITFOR DELAY '00:00:05'-- inurl -.com.my index.php id
Note: A cleaner, more effective version of this dork would be: inurl:index.php?id inurl:.com.my (to specifically hunt within Malaysian commercial sites). The inclusion of the minus sign suggests the user wants to avoid false positives or has a specific reconnaissance target. Never trust user input
If you are a website owner and you recognize your site in a search like inurl -.com.my index.php id, do not panic. Take immediate action. /index