|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 139
Members: 0
Total: 139
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
&nickname=anon&email=abcd@ef.gh&timezone=-12&birthdate=a', '127.0.0.1'); SELECT * from site_infotable --
Query failed:
errorno=1064
error=You have an error in your S ... |
|
|
|
|
If you try:
birthdate=1234
do you get sql error message?
And if you try:
birthdate=abcd
do you see sql error message?
Nope, abcd works just fine. The requests goes through ... |
|
|
|
|
I'm using my own C# application to send a POST request.
The post data I'm sending looks like this:
&nickname=anon&email=abcd@ef.gh&timezone=-12&birthdate=
"&birthdate=" ... |
|
|
|
|
I'm using my own C# application to send a POST request.
The post data I'm sending looks like this:
&nickname=anon&email=abcd@ef.gh&timezone=-12&birthdate=
"&birthdate=" ... |
|
|
|
|
INSERT INTO tablename ( field1, field2, field3, exploitable_field, field5 ) VALUES( 'val1', 'val2', 'val3', '??????', 'val5' )
I've been trying to inject a query into "exploitable_field" and grab ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|