Blind SQL Injection in Search Functionality Leads to Full Database Extraction

Disclosed by
molany
Summary by molany

A blind SQL injection was found on a hidden, non-linked page not reachable through normal crawling. It could not be detected or exploited by sqlmap or Ghauri, both returning false negatives. Manual testing was required to confirm the injection, followed by a custom script to reliably exploit it which is likely why this vulnerability went undiscovered until now.

Activity