by mischief on Sun Jul 19, 2009 7:12 pm
([msg=26987]see Re: SQL Injection in UPDATE query[/msg])
http://marc.info/?l=bugtraq&m=111885974124936&w=2if you read there you can see that someone could insert a rating of their own into the mambo CMS voting system. so, for example, if you were playing a game that used SQL statements that were invalidated and injectable by the user, for example the bonus given to skills when you level up, you could increase your levels several times instead of just one, or however many points it increases.
The whole secret of existence is to have no fear. Never fear what will become of you, depend on no one. Only the moment you reject all help are you freed.
--Buddha