 |
|
 |
 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 308
Members: 0
Total: 308
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
what can i do here |
 |
Posted: Tue May 10, 2005 10:39 pm |
|
|
james |
Beginner |

 |
|
Joined: May 05, 2005 |
Posts: 4 |
|
|
|
 |
 |
 |
|
anything i can do here ? error in query: SELECT * FROM items_data WHERE slot=l337james AND store=\'1\' ORDER BY name ASC Unknown column \'l337james\' in \'where |
|
|
|
|
 |
Re: what can i do here |
 |
Posted: Thu May 12, 2005 12:21 am |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
james wrote: | anything i can do here ? error in query: SELECT * FROM items_data WHERE slot=l337james AND store=\'1\' ORDER BY name ASC Unknown column \'l337james\' in \'where |
As i can understand, sql injection exist after "WHERE". So you can use UNION, JOIN, INTO OUTFILE tricks, but success will depend on mysql server version (if it is mysql at all...). Version 3.x is with limited functionality - so no UNION tricks. Version 4.x will let us use the UNION tricks. And finally, 5.x will introduce the subqueries.
Now, have you information about sql database and table internal structure? If it's opesource softeware, you can look at src code. If it's custom written website, then its more difficult. Any attacker is interested about tables in sql database with most valuable data - logins/passwords/cc/personal data/...
But for this we must know table names. In case of oracle and m$sql there is methods to tables and fields enumeration. In case of mysql ... - well, let's say, it's difficult. Maybe bruteforce... |
|
|
|
|
 |
 |
|
 |
Posted: Thu May 12, 2005 7:48 pm |
|
|
james |
Beginner |

 |
|
Joined: May 05, 2005 |
Posts: 4 |
|
|
|
 |
 |
 |
|
specialty.php?slot=code i think
can you give me expample plz im new at this
38/*!50000%20s*/ Normal screen. MySQL is below 5.x.x
think it that version works good
i know some tables allready |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|