Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Exploiting Second Order SQL Injection with Stored Procedures

Summary

This walkthrough covers exploiting second-order SQL injection in an Excel report export feature, chaining stored procedure UNC path injection via xp_dirtree to exfiltrate database details over DNS.
Published
Collected

original ↗