Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


SQL Injection dateformat=parameter filter_list
Author
Message
SQL Injection dateformat=parameter #1
I have a specific query regarding a SQL injection ive found in the dateformat parameter of a POST request of a PHPBB forum don't ask what its hosting its strange fetish porn... lol

Its mysql14 ---PHPBB board

POST request to ucp.php --- user control panel

dateformat="a"" or 6=6--" ---- before Burp encodes the payload

Servers Response

HTTP/1.1 503 Service Unavailable
Date: Mon, 29 Jul 2019 19:20:16 GMT
Server: Apache
X-Powered-By: PHP/5.6.29
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 2175

<div>SQL ERROR [ mysql4 ]<br /><br />Data too long for column 'user_dateformat' at row 1 [1406]<br /><br />An SQL error occurred while fetching this page. Please contact the <a

I found it on exploit db as well but see no working exploit the link is below

https://www.exploit-db.com/exploits/37551

Reply

RE: SQL Injection dateformat=parameter #2
If anyone can help with this potential injection I would be most greatful Smile

Reply