Rama
Member
- Jan 4, 2011
- 245
- 14
It was discovered a flaw in SQL Injection and butterstrom that possible to use sql commands within the Client.
It works like this:
And one must type the command sql injection option in the navigator 'search'
Immediately following type the following command: >>> owner:'; DROP TABLE users; <<
Does anyone know how to fix this? I'm using the latest version of swift emulator. (I think!)
(Screenie of exploit taking place is on this thread as attactched files)
It works like this:
And one must type the command sql injection option in the navigator 'search'
Immediately following type the following command: >>> owner:'; DROP TABLE users; <<
Does anyone know how to fix this? I'm using the latest version of swift emulator. (I think!)
(Screenie of exploit taking place is on this thread as attactched files)