also javascript and html are used in xss attacks and not sql inject attacks as the syntax is completely different for these attacks. Also no db software is inheriently secure. This attack may not work in MySql but that's not to say that MySql can't be sql injected as this comes from user commands originating from the code the programmer wrote. In reply to: "Skeleton key unlocks Microsoft SQL servers in latest Web attack"
May 7, 2008
0 replies