automation-script

1 article
sort: new top best
clear filter
0 8/10

A detailed writeup on exploiting SQL injection in INSERT queries where commas are forbidden by the application's input filtering logic. The author demonstrates bypassing the comma restriction using CASE WHEN statements with LIKE operators and CAST functions, achieving time-based blind SQL injection to exfiltrate database information.

Ahmed Sultan MariaDB MySQL
blog.redforce.io · devanshbatham/Awesome-Bugbounty-Writeups · 9 hours ago · details