comment-encoding

1 article
sort: new top best
clear filter
0 7/10

Technical writeup demonstrating SQL injection bypass of ModSecurity WAF using MySQL comment encoding (/*!50000*/) and alternative payload construction with MOD/DIV operators and variable assignment to extract WordPress database credentials and schema information.

_Y000_
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 19 hours ago · details