Re: Another Sql Injection

From: Cactus Corp. (nXewsXalaXksaX_at_nXxtg.XnetX)
Date: 08/09/05


Date: Tue, 9 Aug 2005 13:57:58 +0200

I am asking myself how using a 'HAVING' clause could make
your request work. Are you using GROUP BY requests when
someone tries to register ?

Second question, what is your regular expression ? Did you
add the beginning and end of string signs ?

^.....$

antonio