which will create an account with
ID
of 9999 and
privs
of 0. Assuming that the
privs
field is used to determine account privileges, this may enable the
attacker to create an administrative user.
In some situations, when working completely blind, injecting into an
INSERT
statement may enable an attacker to extract string data from the application.
For example, the attacker could grab the version string of the database and
insert this into a field within his own user profile, which can be displayed back
to their browser in the normal way.
Do'stlaringiz bilan baham: