filename-parameter

1 article
sort: new top best
clear filter
0 6/10

A blind time-based SQL injection vulnerability was discovered in a file upload feature where the application stored the filename parameter in a database without proper sanitization. The vulnerability was confirmed by bypassing a Cloudflare WAF configuration issue and using SQL sleep payloads to measure response time differences.

Synack HackerOne Cloudflare WAF Burp Scanner Burp Proxy @reefbr @marcioalm @joaomatosf CVE-2019-2725 Red Hat RSA Authentication Manager Weblogic
jspin.re · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details