Home page logo

pen-test logo Penetration Testing mailing list archives

Missing Operator SQL
From: "DokFLeed" <dokfleed () dokfleed net>
Date: Tue, 5 Jun 2007 13:48:06 +0400

I am testing this local application, not really a big fan of ASP so any =
help is welcome

http://localhost/account.asp?ID=3D12';Exec master..xp_cmdshell 'dir

Microsoft JET Database Engine error '80040e14'
Syntax error (missing operator) in query expression 'D.xID=3D12';EXEC =
master..xp_cmdshell 'dir'.

What is the missing operator for ?


This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]