ferreiraklet/Jeeves

sqlinejction in useragent

r0x5r opened this issue · 3 comments

r0x5r commented

hey can we use sql injection payload in useragent 'XOR(if(now()=sysdate(),sleep(5*5),0))OR' this can you share the command

Yes, since jeeves makes his verification by the request time, you can insert payloads in header

r0x5r commented

can you share the command for this

Yes man, I definitively going to put this on the new readme