webPromedium

Lab 79 — LeadStream — Blind SQL Injection via Excel Bulk Import

hackadvisor

Task: CRM platform with XLSX bulk import feature; email field in uploaded spreadsheet is interpolated into SQLite query without parameterization. Solution: boolean-based blind SQLi via duplicate detection oracle — inject conditions into email cells, use binary search with unicode(substr()) to extract flag from admin_secrets table.

$ ls tags/ techniques/
binary_search_extractionboolean_based_blind_sqlisqlite_unicode_substrxlsx_payload_injectionduplicate_detection_oracleschema_enumeration_sqlite_master

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups