bug-bounty497
google347
xss301
microsoft290
facebook261
rce211
exploit198
malware168
apple161
cve135
account-takeover115
bragging-post102
privilege-escalation96
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering54
access-control52
react52
input-validation49
cross-site-scripting48
cloudflare47
aws47
docker46
web-security46
lfi46
smart-contract45
sql-injection45
web-application44
ethereum44
ctf43
web343
defi43
oauth43
node41
race-condition39
pentest39
open-source39
idor37
cloud37
info-disclosure36
burp-suite36
auth-bypass35
0
9/10
vulnerability
A critical SQL injection vulnerability was discovered in a legacy 404 error handler that directly concatenates user-controlled REQUEST_URI into an INSERT statement without sanitization. The attacker exploited INSERT-based, multi-row XPATH injection combined with EXTRACTVALUE() error-based extraction to bypass automated tools and dump database contents, revealing the application ran with MySQL root privileges.
sql-injection
error-based-sql-injection
xpath-injection
insert-based-injection
extractvalue
legacy-infrastructure
404-handler
php-vulnerability
mysql
information-disclosure
penetration-testing
payload-crafting
multi-row-injection
vulnerability-research
SQLMap
Ghauri
Sublist3r
DNSRecon
Amass
viewdns.info
EXTRACTVALUE
mysqli
Eduardo F
0
5/10
bug-bounty
A researcher discovered a critical SQL injection vulnerability in an abandoned website, exploiting a chain of weaknesses in legacy infrastructure. The writeup details how poor maintenance and outdated systems created an attack surface for database exploitation.