Помогите раскрутить.. короче нашел возможность сделать sql inj
http://beatlive.net.ru/index.php?do=searchнажать расширенный поиск - Поиск по имени пользователя ввести qwerty - поставить галку 'точное имя' и нажать начать поиск - появляется это
Код:
The Error returned was:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'as score, autor, dle_post.date AS newsdate, dle_post.date AS date, short_story A' at line 1
Error Number:
1064
SELECT id, as score, autor, dle_post.date AS newsdate, dle_post.date AS date, short_story AS story, dle_post.xfields AS xfields, title, descr, keywords, category, alt_name, comm_num AS comm_in_news, allow_comm, rating, news_read, '' AS output_comms FROM dle_post WHERE dle_post.approve = '1' AND dle_post.autor like 'qwerty' ORDER BY score DESC, date desc LIMIT 0,20