SQL Injection without these special chars [' "()\/%*&\`] possible?
Yep, me and @or4nge16hehe did it.
Using only: [ a-z, 0-9, dot, @+- ]
Write-up soon
#BugBounty#infosec
SQL Injection without these special chars [' "()\/%*&\`] possible?
Yep, me and @or4nge16hehe did it.
Using only: [ a-z, 0-9, dot, @+- ]
Write-up soon
#BugBounty#infosec
@ksalife_@or4nge16hehe yeah there’s a lot more edge cases tbh, I’ll just make a writeup later cause explaining everything in comments gonna be too long