Weird SQLi or False Positive? 03-13-2015, 04:50 PM
#1
This got posted on HF not long ago - rentagrandma.com/browse-grandmas.php?z=40935&r=10&j=2
What you use to trigger the error is putting \ at the end of the j or z parameters. I tried every other thing that could trigger and and nothing else works.
Apparently it's some big website so I thought I'd take a swing at it. I've tried literally every. single. SQLi method I know and no dice. I even took the time to download SQLmap on my VPS and tried it with risk 3 and level 3 and still fucking nothing.
Can anyone confirm that this is or isn't a real vulnerability that can be exploited?
What you use to trigger the error is putting \ at the end of the j or z parameters. I tried every other thing that could trigger and and nothing else works.
Apparently it's some big website so I thought I'd take a swing at it. I've tried literally every. single. SQLi method I know and no dice. I even took the time to download SQLmap on my VPS and tried it with risk 3 and level 3 and still fucking nothing.
Can anyone confirm that this is or isn't a real vulnerability that can be exploited?




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)