sql injection in Microsoft SQL Server 2017 problem retrieving db names
While I was pentesting, I came across a blind sql injection in a website that uses IIS. I tried this payload " AND 11=11 AND (‘Hlua’=’Hlua" and it works and it gives success page then i tried " AND 11=12 AND (‘Hlua’=’Hlua&qu… Continue reading sql injection in Microsoft SQL Server 2017 problem retrieving db names