IIliyainblog.iliyadindar.site·3d ago · 8 min readIntigriti September 2026 Challenge, Critter GalleryVulnerability: Unauthenticated SQL injection (MySQL 8.0.46) in the base64-encoded pic parameter of /challenge.php, exploited with a single-column UNION SELECT to read the secret_vault table. TL;DR /c00
4F404 Foundersin404-founders.com·4d ago · 2 min readRoundcube CVE-2026-48842: Pre-Auth SQL Injection ExploitedRoundcube CVE-2026-48842: pre-auth SQL injection is being exploited CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail's optional virtuser_query plugin. Roundcube fixed it in ve00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 10 · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 13 · 7 min readCommon Web Application TechnologiesIntroduction Modern web applications are rarely built with a single technology. A typical application combines a web server, a programming language, a framework, a database, data formats, and backend 10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
JAJoyce Abijaincybersage.hashnode.dev·Aug 6 · 5 min readThe Vulnerability That Cost UK's TalkTalk BillionsWhen Cyber attacks happen, we often imagine highly skilled hackers in black hoods armed with sophisticated malware and advanced hacking tools. While those attacks certainly exist, many of the world's 00
SSunnyincybersecurity-learning.hashnode.dev·Jul 22 · 19 min readTryHackMe SQL Injection Beginner-Friendly Learning GuideIntroduction I recently completed the SQL Injection room on TryHackMe as part of my ongoing cybersecurity learning journey. SQL Injection is one of the most important web application security vulnerab00
JJasonincybersage.hashnode.dev·Jul 10 · 11 min readSQL InjectionsWHAT IS SQLi? In this article, we’ll be referring to SQL injections as SQLi. SQLi is a web security vulnerability that allows an attacker to interfere with queries between an application and its datab00
PMPrasanth Madhurapantulainiwtlp.hashnode.dev·Jun 14 · 3 min readSQL injection explained safely with a toy loginSQL injection has been at or near the top of web vulnerability lists for two decades, and yet it is genuinely easy to understand once you see it happen. The safe, legal way to learn it is on a toy log10
WBWiktoria Blomgren Strandberginpentesting-dvwa.hashnode.dev·Apr 26 · 28 min readBlind SQL Injection in DVWA1 Introduction In this post, the Blind SQL Injection vulnerability in the Damn Vulnerable Web Application (DVWA) is described. The objective for attacks on all levels is to find the version of the SQL00