file-write

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered a SQL injection vulnerability in an affiliate form's email parameter, demonstrating information extraction via UNION-based injection and then escalating to arbitrary file read/write using MySQL's LOAD_FILE and INTO OUTFILE functions to exfiltrate /etc/passwd and create files on the server.

Mario Hackerone InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details