This is a technical writeup describing a SQL injection vulnerability in Thatware 0.4.6's friend.php file. The vulnerability stems from the $sid parameter being directly interpolated into a SQL query without sanitization.
Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:Thatware 0.4.6
No auth needed
Prerequisites:Access to the friend.php endpoint with a vulnerable $sid parameter