webPromedium
Lab 203 — PlanFlow — SQL Injection in Team Directory Search
hackadvisor
Task: Agile project management platform with team directory search vulnerable to SQL injection in SQLite. Solution: UNION-based SQLi to enumerate schema via sqlite_master and extract flag from secret_config table.
$ ls tags/ techniques/
union_based_sqlicolumn_count_detectionsqlite_schema_enumerationerror_based_sqli_detection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 3 — DeskFlow — SQL Injection in Ticket View— hackadvisor
- [web][Pro]Lab 83 — DealStream — UNION SQL Injection in Public Search API— hackadvisor
- [web][Pro]Lab 103 — DataPilot — AI SQL Injection via Natural Language Query— hackadvisor
- [web][Pro]Lab 53 — TeamPulse — SQL Injection via WebSocket Employee Lookup— hackadvisor
- [web][Pro]Lab 80 — GateGuard — SQL Injection in Organization Filter API— hackadvisor