Full Disclosure mailing list archives

Re: PoC for the 2 new WMF vulnerabilities (DoS)


From: "Morning Wood" <se_cur_ity () hotmail com>
Date: Tue, 10 Jan 2006 02:07:14 -0800

Michael Bringle
Director of Engineering
PivX Solutions, Inc.
http://www.pivx.com/HomeOffice/

i made a booboo and accidentaly put a ' in your url ( sorry, its right next
to the enter key )
couldnt help but notice this tho...

http://www.pivx.com/Labs/ThreatCenter.asp?sortby=threat_name&apos;

Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
You have an error in your SQL syntax. Check the manual that corresponds to
your MySQL server version for the right syntax to use near '' desc' at line
1
/Labs/ThreatCenter.asp, line 84


http://www.pivx.com/Labs/ThreatCenter.asp?sortby='threat_name

Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
You have an error in your SQL syntax. Check the manual that corresponds to
your MySQL server version for the right syntax to use near ''threat_name
desc' at line 1
/Labs/ThreatCenter.asp, line 84

i am secure in the fact that you dont protect web-apps with your products
!!!
KEEP UP THE SELF PROMOTION !!! YOU ROCK !!! YOUR PRODUCTS WILL SAVE US ALL
!!!
*sigh*

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: