FileFlows Vulnerabilities - SQL Injection by Decompiling .NET Code
projectblack.io | research | #sql-injection | #vulnerability | #decompilation | #dotnet | #fileflows
Summary
Decompiling FileFlows' .NET binaries uncovered a SQL injection in the library-file search endpoint; simple quote replacement was insufficient to stop it on some supported databases.
- Published
- Collected
Skip to content