Forumlar / Cotonti / Bugs / Search SQL injection

Exploit

badc0re
#30752 2011-09-18 21:36
#30749 esclkm:

but where was injection??? this field has ALP filter - which filter only [A-Za-z0-z_] try to inject

 

Added 2 minutes later:

Well the search is vulnerable. Try it by yourself.

Maybe it's not exploitable but it could lead to information extraction.

Bu gönderi badc0re tarafından düzenlendi (2011-09-18 21:46, 13 yıllar önce)