Back to directory
WRITEUP #1046

AWS WAF Clients Left Vulnerable to SQL Injection Due to Unorthodox MSSQL Design Choice

SQL InjectionWAF bypass
byMarc Olivier Bergeron
Program
MicrosoftAWS
Published
Jun 21, 2023
Added to HackDex
Jun 25, 2023
Read Full Writeuphttps://www.gosecure.net/blog/2023/06/21/aws-waf-clients-left-vulnerable-to-sql-injection-due-to-unorthodox-mssql-design-choice/
RELATED WRITEUPS
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL InjectionReverse engineering
Bypassing airport security via SQL injection
SQL Injection
World of SELECT-only PostgreSQL Injections: (Ab)using the filesystem
SQL Injection
Listen to the whispers: web timing attacks that actually work
SSRFTiming attack

Built with ❤️ by Shubham Rawat