time-based-blind-sql-injection

2 articles
sort: new top best
clear filter
0 5/10

A researcher discovered a SQL injection vulnerability in a trading company's reporting download endpoint via a hidden 'status' parameter that was discovered using parameter mining tools, exploitable through time-based blind SQL injection.

Rutvik Hajare OWASP sqlmap Burp Suite
hajarerutik9.medium.com · kh4sh3i/bug-bounty-writeups · 18 hours ago · details
0 7/10

A bug bounty hunter documents their journey discovering a time-based blind SQL injection vulnerability in a sorting parameter by using MySQL version detection via comment syntax to narrow payload scope, ultimately bypassing WAF filters with the payload (select*from(select(sleep(10)))a) and earning a $3500 bounty.

Marx Chryz Del Mundo RootCon Bugcrowd Web Application Hacker's Handbook Web Hacking 101 Stök Farah Hawa Jason Haddix Peter Yaworski James Kettle Dafydd Stuttard
marxchryz.medium.com · kh4sh3i/bug-bounty-writeups · 18 hours ago · details