Hacking SQL Server Stored Procedures – Part 3: SQL Injection
netspi.com | vulnerability | #privilege-escalation | #sql-injection | #sql-server | #stored-procedures | #execute-as
Summary
SQL injection inside stored procedures using dynamic SQL can escalate to sysadmin when procedures run with elevated privileges via WITH EXECUTE AS or certificate signing, as this walkthrough shows.
- Published
- Collected
Skip to content