Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

SQL njection 2

From: falcifer <falcifer2001(at)yahoo.es>
Date: Sun Apr 20 2003 - 16:45:19 EDT


how can i insert an isert command in a sql sentence that looks like select * from parameter???
the database is access and when i try to insert something like

pameter=table;insert%20into%20clientes(uspw,pwus)%20values('j','j')

the ODBC returns this error

error '80040e14'

[Microsoft][Controlador ODBC Microsoft Access] Se encontraron caracteres después del final de la instrucción SQL.

/visornew.asp, line 10

it means: "there are characteres after the the sql sentence"

-- 
falcifer 
Received on Sun Apr 20 14:48:58 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT

Do you need help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library