Thread: Inject away...
View Single Post
Old 06-18-2004, 05:37 PM  
jwerd
Confirmed User
 
Industry Role:
Join Date: Jun 2003
Location: Costa Rica
Posts: 1,953
Inject away...

I set up a small script on my site that looks for a GET type variable, and looks up a username. Now this is just a test script, your objective is to delete the user John. Can you do it?

Column name is username
Table name is exploit
Value inside we are wanting to delete John.
Variable name sql
Can you guys do it?

http://www.lamerhood.com/exploits/sq...p?sql=whatever

err sorry, it's "john" not "John". And I'll let you guys know if it works or not
__________________
Yii Framework Guru - Seasoned PHP vet - Partner @ XXXCoupon.com

Last edited by jwerd; 06-18-2004 at 05:42 PM..
jwerd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote