绕过Apache Superset限制执行SQL注入
blog.quarkslab.com | 研究 | #sql-injection | #postgresql | #vulnerability | #pentest | #apache-superset | #bypass
摘要
Quarkslab 在审计中发现 Apache Superset 防 SQL 注入措施的绕过方法:通过研究 PostgreSQL 文档绕开其子查询校验,在 explore_json 与 chart/data 接口实现注入,并将时间盲注转化为报错注入。
- 发布时间
- 收录时间
Skip to content