webPromedium

Lab 3 — DeskFlow — SQL Injection in Ticket View

hackadvisor

Task: IT service management platform (DeskFlow) with ticket system, ticket detail endpoint /tickets/{id} vulnerable to SQL injection via path parameter. Solution: UNION-based SQLi with 11 columns to extract master_api_key from system_config table in SQLite database.

$ ls tags/ techniques/
union_based_sql_injectionboolean_based_sqli_confirmationorder_by_column_enumerationsqlite_master_schema_extractiondecoy_flag_detection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups