extractvalue

2 articles
sort: new top best
clear filter
0 9/10

A critical SQL injection vulnerability was discovered in a legacy 404 error handler that directly concatenates user-controlled REQUEST_URI into an INSERT statement without sanitization. The attacker exploited INSERT-based, multi-row XPATH injection combined with EXTRACTVALUE() error-based extraction to bypass automated tools and dump database contents, revealing the application ran with MySQL root privileges.

SQLMap Ghauri Sublist3r DNSRecon Amass viewdns.info EXTRACTVALUE mysqli Eduardo F
infosecwriteups.com · Eduardo F · 3 hours ago · details
0 5/10

SQL injection vulnerability discovered in Nutanix's bootcamp.nutanix.com login endpoint accepting JSON POST requests. Error-based SQLi via email parameter revealed MySQL version 8.0.11 using extractvalue() payload; exploitable through JSON API without authentication.

bootcamp.nutanix.com Nutanix Muhammad Khizer Javed Express MySQL 8.0.11
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details