storage-plugin

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a Local File Inclusion (LFI) vulnerability in Apache Drill by manipulating the dfs storage plugin configuration to read arbitrary files from the server, such as /etc/passwd, via crafted SQL queries.

Apache Drill HackerOne Jobert Abma Gujjuboy10x00 Freedium
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 9 hours ago · details