TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

What to do after discovering SQL Injection vulnerability in random websites?

3 pointsby mariocarvalhoabout 11 years ago
After playing a little with Vega - I'm newbie in web auditions, just trying to learning something new - and auditing some websites I can see that 8/10 websites have SQL Injection vulnerabilities classified by Vega as High. What should I do here? Email the website owner?

2 comments

pktgenabout 11 years ago
I would be very, very, very careful here. Not sure what country you're in, but you're setting yourself up for possible legal action, even though your intentions are good.
gk1about 11 years ago
You can email the owner with a few tips to fix the issue. You can even offer to do a deeper inspection for some fee.
评论 #7292232 未加载