Re: Re: Invision Gallery 2.0.6 ( SQL Injection )From: an0n () netc com Date: 5 May 2006 16:43:18 -0000
I checked this yesterday night. The pass_hash is well retrieved, but modifying the pass_hash and the user id in the
cookies (thanks to BurpSuite) does not affect the behaviour of the server... I might have done something wrong...