webPromedium
Lab 3 — DeskFlow — SQL Injection in Ticket View
hackadvisor
Task: IT service management platform (DeskFlow) with ticket system, ticket detail endpoint /tickets/{id} vulnerable to SQL injection via path parameter. Solution: UNION-based SQLi with 11 columns to extract master_api_key from system_config table in SQLite database.
$ ls tags/ techniques/
union_based_sql_injectionboolean_based_sqli_confirmationorder_by_column_enumerationsqlite_master_schema_extractiondecoy_flag_detection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]DeskFlow — Session Fixation via Support Ticket URL— hackadvisor
- [web][Pro]Lab 203 — PlanFlow — SQL Injection in Team Directory Search— hackadvisor
- [web][Pro]Lab 83 — DealStream — UNION SQL Injection in Public Search API— hackadvisor
- [web][Pro]MetricFlow— hackadvisor
- [web][Pro]Lab 168 — MetricFlow — Insecure Deserialization via Dashboard Import— hackadvisor