Back to directory
WRITEUP #4614

Utilizing Lockdown: Blind Sqli leads to Account Takeover & Data Extraction

SQL InjectionBlind SQL injectionAccount takeover
by@3ncryptSaan(Shakti Mohanty)
Bounty
1,400
Program
-
Published
Jun 10, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@shakti.gtp/utilizing-lockdown-blind-sqli-leads-to-account-takeover-data-extraction-3705ce8bdb62
RELATED WRITEUPS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Self-XSS to ATO via Site Features
XSSSelf-XSS
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL InjectionReverse engineering
Bypassing airport security via SQL injection
SQL Injection

Built with ❤️ by Shubham Rawat