SQL injection LAB 7 UNION attack, listing the database contents on non-Oracle databases
Автор: Saga Learns
Загружено: 2026-02-25
Просмотров: 5
Описание:
We will be covering the 7th lab for SQL Injection for Portswigger Web Security Academy.
This lab contains a SQL injection vulnerability in the product category filter. The results from the query are returned in the application's response so you can use a UNION attack to retrieve data from other tables.
The application has a login function, and the database contains a table that holds usernames and passwords. You need to determine the name of this table and the columns it contains, then retrieve the contents of the table to obtain the username and password of all users.
To solve the lab, log in as the administrator user.
--
Join along at Portswigger:
https://portswigger.net/web-security
SQL Injection Labs:
https://portswigger.net/web-security/...
More information on SQL Injection:
https://owasp.org/www-community/attac...
--
Feedback is welcome.
If you found value, please leave a sub and a like. Maybe share it?
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: