this turkish news script accepts sql injection, but there are no results (i can not inject char). this is very important bug, because there are several thousand sites with this script!
u can use subqueries with sql one char bruteforce, in fact the script probably selects one item from news that contents all the text and other info about it (there exist two or more queries for this parametr and they have different number of collumns) so u cant output the info directly
__________________
Привет! Меня зовут Джордж, и я хотел бы рассказать вам про реинкарнацию (ц) 2x2
Последний раз редактировалось blackybr; 31.03.2008 в 12:30..