|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 98
Members: 0
Total: 98
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
SQL Injection... How to? |
|
Posted: Thu Apr 26, 2007 6:34 am |
|
|
Woet |
Beginner |
|
|
Joined: Apr 26, 2007 |
Posts: 3 |
|
|
|
|
|
|
|
I would like to make this query DELETE the news table, DROP the news table or whatever.
Code: | SELECT vwar_news.*, name, catname, caticon
FROM vwar_news
LEFT JOIN vwar_member ON (vwar_news.memberid = vwar_member.memberid)
LEFT JOIN vwar_newscat ON (vwar_news.catid = vwar_newscat.catid)
WHERE activated = '1'
AND vwar_news.catid IN ('2') AND vwar_news.catid = '2'
GROUP BY newsid
ORDER BY [] desc, vwar_news.dateline DESC
LIMIT 0, 10 |
The place of the [] is where I can put my own code.
This is the query result of my url:
news.php?sortby=[] |
|
|
|
|
Posted: Sat May 05, 2007 11:05 am |
|
|
Woet |
Beginner |
|
|
Joined: Apr 26, 2007 |
Posts: 3 |
|
|
|
|
|
|
|
|
|
|
|
Posted: Sat May 05, 2007 2:59 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
If this is MySql, then sql injection after "ORDER BY" has limited possibilities and you cant do "DROP", "ALTER" or something else like that.
There can be MAYBE possible to steal some data from database, but this depends on MySql version. |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|