question bout prepared statements in php
by zinzeur - Tuesday October 3, 2023 at 10:37 PM
#1
Is it possible to do sQl injection against website using prepared statement for querying the database ? thanks for your help
Reply
#2
its literally called sql INJECTION
just INJECT the " ' " symbol into the query to see if the db is vulnerable
Reply
#3
https://overflow.datura.network/question...-injection
Reply
#4
(Oct 03, 2023, 10:39 PM)XxG1izzi3Guzzl3RxX Wrote: its literally called sql INJECTION
just INJECT the " ' " symbol into the query to see if the db is vulnerable

thanks but prepared statements are the way to guard against sql injections so it would be useless trying classic injection payloads, what I'm looking is if there are edge cases where injection is possible with some clever way

(Oct 03, 2023, 10:41 PM)Kurumi Wrote: https://overflow.datura.network/question...-injection

thanks a lot , best regards
Reply
#5
No, unless there's in bug in the prepared statments code.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Acunetix 23.7 lolol 37 7,134 Yesterday, 09:37 AM
Last Post: Usercomplex
  [FREE] Database Searcher Telegram odanbtw 1,004 80,255 Apr 24, 2026, 12:13 PM
Last Post: FAKE_NBOBN00
  ✅ Top 10 Google Dorks For SQL Injections NextSoftGroup 9 217 Apr 24, 2026, 02:54 AM
Last Post: elliotalderson4
  [2026] Bypass AV / EDR Spearr 62 769 Apr 24, 2026, 02:44 AM
Last Post: elliotalderson4
  Cardable Giftcard Websites AKASHIC 8 237 Feb 10, 2026, 01:08 PM
Last Post: mreai

Forum Jump:


 Users browsing this forum: 1 Guest(s)