Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp)
Hi JC

Quite interesting.
But I couldn't get it work.

It works fine on query analyser,
but it didn't work when I try it on the application side (on the browser).
(I used %0d%0a for the newline character)

May be it depends on the version of MSSQL or the service pack etc.
Could you tell us the versi...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus