webPromedium

Lab 203 — PlanFlow — SQL Injection in Team Directory Search

hackadvisor

Task: Agile project management platform with team directory search vulnerable to SQL injection in SQLite. Solution: UNION-based SQLi to enumerate schema via sqlite_master and extract flag from secret_config table.

$ ls tags/ techniques/
union_based_sqlicolumn_count_detectionsqlite_schema_enumerationerror_based_sqli_detection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups