|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 88
Members: 0
Total: 88
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Supposedly simple but I think I'm doing something wrong |
|
Posted: Thu Jun 02, 2011 6:37 pm |
|
|
Boon |
Beginner |
|
|
Joined: Jun 02, 2011 |
Posts: 1 |
|
|
|
|
|
|
|
Hi, I'm trying to inject into this query
Code: |
mysql_query("INSERT INTO pollanswers VALUES(0, $pollid, $userid, $choice)") or sqlerr(); |
all the php variables except $choice are irrelevant and for example's sake we can pretend they all are 1.
The server is running MySQL.
I have control over the $choice parameter
and my goal is to execute this query
Quote: | UPDATE USERS SET CLASS=9 WHERE ID=219141 |
I came up with something like this:
Quote: | 3); UPDATE USERS SET CLASS=9 WHERE ID=219141;-- |
but I get this error
Quote: | SQL Error
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'UPDATE USERS SET CLASS=9 WHERE ID=219141;--)' at |
It seems like /* and -- do nothing and I'm left with an extra )
So I came up with this
Quote: | 3); UPDATE USERS SET CLASS=9 WHERE ID=(219141 |
And now I get THIS error
Quote: | SQL Error
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'UPDATE USERS SET CLASS=9 WHERE ID=(219141)' at line 1 |
Now I'm stumped, what am I doing wrong? |
|
|
|
|
|
|
|
|
Posted: Fri Jun 10, 2011 7:43 am |
|
|
RubberDoll |
Active user |
|
|
Joined: Jun 04, 2009 |
Posts: 46 |
|
|
|
|
|
|
|
Did you try not yo use the semi-colon?
instead maybe use ID=219141-- only
And how do you know you have update permission? |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|