Another late CTF writeups for H@cktivitycon 2021 web category.
Second-order SQL injection
DC-9 from VulnHub features a website that is vulnerable to SQL injection. I’m able to dump a bunch …
SQLi for login bypass and embed webshell to an image file