vulnerable-search-parameter

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered and exploited a SQL injection vulnerability in the University of Cambridge's Fitzwilliam Museum search functionality, demonstrating column enumeration via ORDER BY, UNION SELECT attacks, and successful extraction of database version, user credentials, and database name.

University of Cambridge Adesh Kolte Fitzwilliam Museum MySQL 5.1.39
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details