hidden-parameter

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered a SQL injection vulnerability in a trading company's reporting download endpoint via a hidden 'status' parameter that was discovered using parameter mining tools, exploitable through time-based blind SQL injection.

Rutvik Hajare OWASP sqlmap Burp Suite
hajarerutik9.medium.com · kh4sh3i/bug-bounty-writeups · 19 hours ago · details