Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Hacking Web 2.0 Applications with Firefox
Shreeraj Shah

Comments Mode:
Hacking Web 2.0 Applications with Firefox 2006-10-12
Anonymous
Though information is passed through the querystring for the server requests shown in this article, that does not make the web application vulnerable to SQL injection techniques. Potentially, vulnerable, yes. Actual vulnerability depends on how the server is validating the data. Though certainly the password shouldn't be passed through without SSL as shown above, there's nothing inherently wrong with the way information is being sent via asynchronous JS.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1879/711#711
Hacking Web 2.0 Applications with Firefox 2006-10-12
Zachary Richmond (1 replies)
Good article but.. 2006-10-16
Zachary Richmond







 

Privacy Statement
Copyright 2008, SecurityFocus