sql injection help

Статус
Закрыто для дальнейших ответов.
I think i have found a SQL injection vulnerbility on a website if im not wrong anytime you put a ' qoute or else behind a parameter
example
http;//example;com/itemid49=1'

And it makes some changes to the website after fiffiling a bit with it on burp


Page changed its when adding a qoute '' to the url parameter itemid49 and fiffiling with requests in burp suite.

Will anyone help? Someone with experince in mySQL Databases how they act and is this a vulnerbility at all?

Havent run it through Sqlmap dont want to make noise in the logs and awake ped admin up early .

Need to exploit this quietly with manual burp requests .

I Will pay $ for help $ if you know how to exploit this.
just add me on my jabber aptops@exploit.im or send me TOX
 

Вложения

  • pagechanged.png
    pagechanged.png
    43.5 КБ · Просмотры: 19
  • pagenotchanged.png
    pagenotchanged.png
    49.4 КБ · Просмотры: 19
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
PM me the target
 
Статус
Закрыто для дальнейших ответов.
Верх