[<prev] [next>] [day] [month] [year] [list]
Message-ID: <f7ba524d0612261628y4a23cc05tf318fb7298cbe29a@mail.gmail.com>
Date: Tue, 26 Dec 2006 19:28:57 -0500
From: icecoldeuro@...il.com
To: full-disclosure@...ts.grok.org.uk
Subject: Re: SQID v0.2 - SQL Injection Digger.
So - hypothetically - the first result of the sample run at
sqid.rubyforge.org would only yield a Microsoft OLE DB provider error (Unclosed
quotation mark before the character string).
Now, granted, this is bad practice if they can't trap their errors, but I
also don't see how this constitutes proof of an XSS vulnerability. The usual
XSS variations - again, purely hypothetically - all just yield the same
error message.
Would you consider this a potential false positive then? In my opinion it's
not a vuln unless it's exploitable.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists