writeups.xyz writeups.xyz / SQL Injection

Title Vulnerabilities Programs Authors
Dolibarr : unauthenticated contacts database theft
I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability.
How I got Owned A Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection
Vulnerability write-up - "Dangerous assumptions"
Securing Open-Source Solutions: A Study of osTicket Vulnerabilities
Blind Time-based SQL injection vulnerability in an Indian government website
SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs
MyBB <= 1.8.31: Remote Code Execution Chain
Bypassing Cloudflare WAF: XSS via SQL Injection
thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
CVE-2022-38627: A journey through SQLite Injection to compromise the whole enterprise building
Getting Secret Key to Building Custom Burp Extension
How I found multiple critical bugs in Red Bull
Exploiting an SQL injection with WAF bypass
How I Hacked A Company (My First Red Team Engagement 🚩)Permalink
{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF
A03:2021 — [Injection] SQL Injection through internal directory disclose
From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)
Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access
A great weekend hack(worth $8k)
CVE-2022-40300: SQL Injection In Manageengine Privileged Access Management
How I get +10 SQLi and +30 XSS via Automation Tool
Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk
SSD Advisory – Cisco Secure Manager Appliance remediation_request_utils SQL Injection Remote Code Execution