UNION-based SQL injection: dumping the user table from a product filter
A category filter concatenates the `category` query parameter straight into a SQL query. This write-up takes it from a single quote to the full credentials table with a UNION SELECT.
The full write-up is locked
Unlock the step-by-step write-up, screenshots and PoC file by purchasing this listing.
A category filter concatenates the `category` query parameter straight into a SQL query. This write-up takes it from a single quote to the full credentials tabl...…
Browse the file tree freely — unlock to download.
-
union_dump.py 1.8 KB
SQL injection labs
View all labsReviews & Questions
Sign in to ask a question or leave a review.
No reviews or questions yet — be the first.
Listing Details
- Author
- x00sec
- Published
- 2026-09-13
- Target / OS
- PHP + MySQL storefront (product category filter)
- Category
- Web Apps
- Payout Method
- No preference
Price
0.0180 BTC
≈ $1,170.00
Live Chat
Ask the seller or other buyers a question — mention someone with @handle
No messages yet — start the conversation.
Sign in to join the conversation.