如所示,DB2可能容易受到SQL注入的影响:
* Potential SQLinjection if X, Y or Z host variables come from untrusted inputSTRING "INSERT INTO TBL (a,b,c) VALUES (" X "," Y "," Z ")" INTO MY-SQL.EXEC SQL PREPARE STMT F
我运行SQLMAP来测试其中一个站点的SQL注入,并获得以下信息。sqlmap identified the following injection points with a total of 78 HTTP(s) requests:Place: GETVistaback-end DBMS: Microsoft SQLServer 2005
我不知