|
|||||||||||
|
Cold Fusion and Sql Injection
From: George Fekkas <G.Fekkas(at)encode-sec.com>
Date: Fri Jun 20 2003 - 13:12:35 EDT Any views expressed in this message are those of the individual sender, except where the sender specifically states them to be the views of ENCODE S.A. ODBC Error Code = 22005 (Error in assignment) [Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value âmy parameter hereâ to a column of data type int. For example, if I place a simple quote I get the following: Syntax error converting the nvarchar value âââ to a column of data type int. Or if I place a @@Version function I get the following: Syntax error converting the nvarchar value â@@Versionâ to a column of data type int. Etc.. Normally, when you pass a single quote as a parameter, the Server returns the following: George Latest attack techniques. You're a pen tester, but is google.com still your R&D team? Now you can get trustworthy commercial-grade exploits and the latest techniques from a world-class research group. Visit us at: www.coresecurity.com/promos/sf_ept1 or call 617-399-6980 Received on Fri Jun 20 15:05:07 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:38 EDT |
||||||||||
|
|||||||||||