Full Disclosure mailing list archives
Re: SQID v0.2 - SQL Injection Digger.
From: icecoldeuro () gmail com
Date: Tue, 26 Dec 2006 19:28:57 -0500
So - hypothetically - the first result of the sample run at sqid.rubyforge.org would only yield a Microsoft OLE DB provider error (Unclosed quotation mark before the character string). Now, granted, this is bad practice if they can't trap their errors, but I also don't see how this constitutes proof of an XSS vulnerability. The usual XSS variations - again, purely hypothetically - all just yield the same error message. Would you consider this a potential false positive then? In my opinion it's not a vuln unless it's exploitable.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- SQID v0.2 - SQL Injection Digger. Metaeye SG (Dec 22)
- <Possible follow-ups>
- Re: SQID v0.2 - SQL Injection Digger. icecoldeuro (Dec 26)