On Tue, Mar 2, 2010 at 4:17 PM, Samisa Abeysinghe <sam...@wso2.com> wrote:

> https://wso2.org/jira/browse/CARBON-6179
>
> <https://wso2.org/jira/browse/CARBON-6179> '%' character can be used to
> list all Users
>
> Have we tried SQL injecting in testing??
>

You can do more things... But these do not get exposed due to a JSP error.
There is a mail on @Architecture (before it was made public).

/sumedha



>
> Thanks,
> --
> Samisa Abeysinghe
> Director, Engineering - WSO2 Inc.
>
> http://wso2.com/ - "lean . enterprise . middleware"
>
> _______________________________________________
> Carbon-dev mailing list
> Carbon-dev@wso2.org
> https://mail.wso2.org/cgi-bin/mailman/listinfo/carbon-dev
>
>
_______________________________________________
Carbon-dev mailing list
Carbon-dev@wso2.org
https://mail.wso2.org/cgi-bin/mailman/listinfo/carbon-dev

Reply via email to