Menu

#28 INSERT SQL Inection

new
Chuck
None
OWASP Vicnum
High
Current
2014-11-25
2012-03-15
anonymous
No

After guessing the correct number, intercepting the request to /vicnum/cgi-bin/vicnum3.pl and changing the POST variables to something like :

player=a&cnt=7),("nomnom",99999,0)-- - &VIEWSTATE=MTY3

Will insert a second entry in the table.

Discussion


Log in to post a comment.