Web Security
[ Home ] [ Slides ] [ Examples ] [ Exercises ] [ Resources ]

Solution: Injection Flows

Study the script

Using the search functionality of your guestbook (version 2, downloaded last week), try to execute some other functionalities. Those attacks where easy because we have already disabled the magic_quote option. The following attacks work also if the option is on.

More realistic attacks


Copyright Emmanuel Benoist 2008-2013