3

After finding SQLi on an internal application during its security review:

DB team: Well it's a remote database, so you're just seeing HTML...wait why do you see user accounts in that web field?

Comments
Add Comment