1. Anuncie Aqui ! Entre em contato fdantas@4each.com.br

[SQL] SQL Injection Bypass non decoding of URL characters Problem [closed]

Discussão em 'Outras Linguagens' iniciado por Stack, Novembro 7, 2024 às 11:22.

  1. Stack

    Stack Membro Participativo

    I'm trying to exploit an SQL injection in one of HTB's challenges, the SQL injection is exploitable by inserting the payload in a similar manner to this : /api/images/ the page returns an error indicating the SQL query and an error if I insert any non numeric characters, the special characters (such as * / , " ' > ? .) are detected and blocked and URL encoded values are passed directly to the query without decoding, is there anyway to bypass these issues ? FYI, the backend language is PHP.

    Continue reading...

Compartilhe esta Página