i have found a Blind Sql injection in the arsenal club website ,so i reported it to them,they didnt respond so why would i care ,i can take over the web site by now but i will just leak the users information ,so may be now they will notice some thing .
SQLI FOUND IN :http://cn.arsenal.com/newsdetail.php?id=%Inject_Here%494
if you want to see the users emails and passwords hit this LINK
SQLI FOUND IN :http://cn.arsenal.com/newsdetail.php?id=%Inject_Here%494
if you want to see the users emails and passwords hit this LINK
0 commentaires:
Enregistrer un commentaire