|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 83
Members: 0
Total: 83
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
x303 |
|
Replies: 3 |
Views: 10692 |
|
|
|
|
|
|
Greetings!
Is it possible to inject a INSERT or UPDATE request?
im not sure UNION can do this....
ex.
mysql_query("SELECT * FROM my_table WHERE name='$name'");
then i type: http://www/?name=1 UNI ... |
|
|
|
x303 |
|
Replies: 5 |
Views: 13265 |
|
|
|
|
|
|
I've tried ( " ) too, same thing happens. Well, maybe it's filtred
Anyway thanx. Ive noticed that LOTS of sites arent filtring user input.. |
|
|
|
x303 |
|
Replies: 5 |
Views: 13265 |
|
|
|
|
|
|
I've found it in ?id= ' ) are replaced by ( \' ) and then nothing is working like it should
So is there a way how to avoid this?
And another question, is it available to inject PHP script ? ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|