V
V
Vyacheslav Lebedev2014-08-25 00:17:41
SQL
Vyacheslav Lebedev, 2014-08-25 00:17:41

Is it possible to conduct sql-inj or some other not 'good' dirty trick, having found something like this?

Occasionally I check sites for sql injections, out of curiosity!
And now, for the first time, a site was found with an error thrown out on the screen :)
http://cp.ketrawars.ru/'login
And here is the thrown error:

ErrorException [ Fatal Error ]: Call to a member function render() on a non-object | 
APPPATH/system/classes/Kohana/Controller/Template.php:44

It is very interesting how this "exploit?" can be used?
And be so kind as to throw something to read on this topic (since the question has appeared).
THANK!

Answer the question

In order to leave comments, you need to log in

1 answer(s)
S
Sergey, 2014-08-25
@slavikse

This bug doesn't affect the database, and you won't be able to call the code on the server, so there's not much you can do here.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question