Back to directory
WRITEUP #1025

Why ORMs and Prepared Statements Can't (Always) Win

SQL InjectionRCESecurity code review
by@swapgs(Thomas Chauchefoin)
Program
SokoGentoo Linux
Published
Jun 26, 2023
Added to HackDex
Jul 12, 2023
Read Full Writeuphttps://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/
RELATED WRITEUPS
Exploiting authorization by nonce in WordPress plugins
RCEArbitrary file upload
Getting code execution on Veeam through CVE-2023-27532
RCEInsecure deserialization
Spip Preauth RCE 2024: Part 2, A Big Upload
RCEFile upload
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL InjectionReverse engineering
Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle
RCESecurity code review

Built with ❤️ by Shubham Rawat