xsspresso
xsspresso
Tags/ SQLi

SQLi

12 writeups tagged with SQLi

WebMediumWindows

VHL — Trace

IIS 10.0 running Kartris eCommerce on Windows. SQL injection and .NET deserialization chain leads to code execution and privilege escalation.

#IIS#Kartris#SQLi
Feb 15, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Fed

Custom PHP forum on Fedora Linux with MariaDB. SQL injection bypasses authentication, leading to file write and shell upload.

#PHP#SQLi#MariaDB
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Records

OpenEMR medical records application. Exploited a pre-auth SQL injection CVE and file upload for shell access.

#OpenEMR#SQLi#File Upload
Feb 11, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Helpdesk

FTP with anonymous access reveals helpdesk application credentials. SQL injection and file upload lead to remote code execution.

#FTP#SQLi#File Upload
Feb 10, 2025Virtual Hacking Labs
ADMediumWindows

HTB — StreamIO

SQLi on login page, LFI reveals PHP source. MSSQL xp_cmdshell for shell. Firefox DPAPI credential decryption leads to Domain Admin via ADCS.

#AD#SQLi#LFI
Jan 31, 2025HackTheBox
WebMediumLinux

HTB — Magic

Magic Portfolio with SQLi bypass on login. File upload bypass with double extension for PHP webshell. mysqldump credential extraction and SUID sysinfo for root.

#SQLi#File Upload Bypass#SUID
Jan 20, 2025HackTheBox
WebMediumLinux

HTB — Monitored

Nagios XI SNMP credential leak, auth bypass CVE-2023-40931 for API key theft. SQL injection creates admin account for RCE via malicious script.

#Nagios#SNMP#SQLi
Jan 19, 2025HackTheBox
WebEasyLinux

HTB — Usage

Laravel admin panel SQL injection via search parameter. Malicious PNG for RCE via file upload. Wildcard file read on sudo binary for root flag.

#SQLi#Laravel#File Upload
Jan 15, 2025HackTheBox
WebMediumWindows

HTB — Giddy

SQL injection via stored procedure triggers NTLM hash capture. Responder catches hash, crack for WinRM. Ubiquiti UniFi privesc via service abuse.

#SQLi#NTLM#Responder
Nov 25, 2024HackTheBox
WebMediumLinux

HTB — Jarvis

SQL injection in hotel booking app. Sqlmap writes a PHP webshell. Sudo script with command injection, SUID systemctl for root.

#SQLi#Webshell#Sudo
Apr 30, 2022HackTheBox
WebEasyLinux

HTB — Swagshop

Magento 1.9 SQLi creates an admin account; Magento Froghopper achieves RCE. Sudo vim executes a shell as root.

#Magento#SQLi#RCE
Apr 13, 2022HackTheBox
WebMediumLinux

HTB — Cronos

DNS zone transfer reveals hidden vhosts. SQL injection login bypass, OS command injection for shell, cron privesc.

#DNS#SQLi#Command Injection
Mar 27, 2022HackTheBox