Date:
02 March 2007
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting, SQL Injection
While vulnerabilities in public web sites are dime a dozen this days and rarely included in WHID, a classic SQL injection in the login form on the home page of the web site of a very big company is worth an entry. In my presentation I usually claim that such vulnerabilities have disappeared years ago and then go on to show advanced SQL injection techniques. It seems that they exit.
References: