Bugtraq mailing list archives

Re: SQL injection in Invision Power Board v2.1.5


From: optix_prorat100 () yahoo com
Date: 5 Apr 2006 12:14:54 -0000

mySQL query error: SELECT pid,topic_id FROM ibf_posts WHERE topic_id=19482 and queued=0 ORDER BY pid asc LIMIT -1,20

SQL error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the 
right syntax to use near '-1,20' at line 1
SQL error code: 
Date: Wednesday 05th of April 2006 01:34:34 PM

this is what it shows 
so ........
?????!!!


Current thread: