phpmyadmin

1 article
sort: new top best
clear filter
0 3/10

A researcher discovered SQL injection on a subdomain to extract admin credentials, then leveraged those credentials to access phpMyAdmin on a different subdomain and achieved remote code execution via a PHP shell upload using MySQL's INTO OUTFILE command.

Jerry Shah HackerOne BugCrowd crackstation.net pentestmonkey.net MySQL
shahjerry33.medium.com · kh4sh3i/bug-bounty-writeups · 22 hours ago · details