Dual Stage SQL Injection Attacks

Martin Paul Eve · 2009

I came across quite an interesting SQL Injection scenario today. The software in which the vulnerability resides will remain anonymous until fixed, but an abstracted version of the scenario can safely be outlined below. The objective of the software is to restrict user accounts to certain IP addresses when accessing a bulletin board.

Read the paper · More papers on PaperTik