Cafe Club| February 22 | Bugforge | Walkthrough Video| SQL injection
Автор: Pranaya
Загружено: 2026-02-23
Просмотров: 1
Описание:
Today’s challenge involved testing an e-commerce style app with products, cart, loyalty points, and reviews. Initially, I explored business logic flaws (review spam, loyalty abuse), but the real issue was deeper.
While analyzing the product/{id} endpoint, I noticed structured fields being returned — a strong hint of a backend SQL query.
After testing the numeric ID parameter, I confirmed a UNION-based SQL Injection vulnerability. By matching the column count and injecting a crafted query, I was able to retrieve concatenated usernames and passwords — including the flag.
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: