bug-bounty449
google354
xss340
microsoft283
facebook246
apple171
exploit163
rce160
malware102
account-takeover95
cve91
bragging-post84
csrf83
browser77
writeup76
privilege-escalation68
react60
authentication-bypass57
cloudflare54
dos53
node52
ssrf51
docker51
phishing50
aws48
access-control47
oauth45
smart-contract45
supply-chain44
ethereum43
web342
defi42
sql-injection41
lfi37
idor35
vulnerability-disclosure32
smart-contract-vulnerability32
info-disclosure31
race-condition31
burp-suite31
web-application31
reverse-engineering31
clickjacking31
wordpress30
information-disclosure29
cloud29
input-validation29
web-security28
reflected-xss27
solidity27
0
7/10
vulnerability
Technical writeup demonstrating SQL injection bypass of ModSecurity WAF using MySQL comment encoding (/*!50000*/) and alternative payload construction with MOD/DIV operators and variable assignment to extract WordPress database credentials and schema information.
sql-injection
waf-bypass
mod-security
mysql
wordpress
union-based-injection
comment-encoding
information-schema
database-enumeration
_Y000_