question bout prepared statements in php
by zinzeur - Tuesday October 3, 2023 at 10:37 PM
#1
Is it possible to do sQl injection against website using prepared statement for querying the database ? thanks for your help
Reply
#2
its literally called sql INJECTION
just INJECT the " ' " symbol into the query to see if the db is vulnerable
Reply
#3
https://overflow.datura.network/question...-injection
Reply
#4
(Oct 03, 2023, 10:39 PM)XxG1izzi3Guzzl3RxX Wrote: its literally called sql INJECTION
just INJECT the " ' " symbol into the query to see if the db is vulnerable

thanks but prepared statements are the way to guard against sql injections so it would be useless trying classic injection payloads, what I'm looking is if there are edge cases where injection is possible with some clever way

(Oct 03, 2023, 10:41 PM)Kurumi Wrote: https://overflow.datura.network/question...-injection

thanks a lot , best regards
Reply
#5
No, unless there's in bug in the prepared statments code.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [2026] Bypass AV / EDR Spearr 63 1,139 5 hours ago
Last Post: AKASHIC
  Unlimited Free Cloud who 105 7,842 5 hours ago
Last Post: AKASHIC
  Bypassing Modern AV (Metasploit Method) godco99 9 500 5 hours ago
Last Post: AKASHIC
  0day-Mari Bot Godfather1 76 7,056 7 hours ago
Last Post: akira2k
  [FREE] Database Searcher Telegram odanbtw 1,021 87,137 Yesterday, 10:08 AM
Last Post: hexaagent00

Forum Jump:


 Users browsing this forum: 1 Guest(s)