Writeups
-
Easy
SQL injection attack, listing the database contents on non-Oracle databases
UNION-based SQL injection from a single broken quote all the way to the admin login - fingerprinting columns, digging table and column names out of information_schema, and dumping the credentials
SQL Injection (SQLi) 6 min -
Easy
SQL Injection Attack, Querying the Database Type and Version on MySQL and Microsoft
category filter takes instructions it shouldn't. We slip it a UNION SELECT with @@VERSION and walk away with the database version
SQL Injection (SQLi) 4 min -
Easy
SQL injection attack, querying the database type and version on Oracle
The filter thinks it's sorting products , and it's running whatever SQL we hand it. we hand it a UNION query and Oracle spills its version
SQL Injection (SQLi) 4 min -
Easy
SQL injection vulnerability allowing login bypass
when the login form trusts your input a little too much
SQL Injection (SQLi) 2 min -
Easy
SQL Injection Vulnerability in WHERE Clause Allowing Retrieval of Hidden Data
When "show me the products" quietly becomes "show me everything"
SQL Injection (SQLi) 4 min -
Easy
What is PortSwigger and the BSCP Certification?
PortSwigger 3 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters