This is the vulnerability where we will learn to do SQLi in user-agent
 
First reload the page and capture the GET request in burp
 
Send the request to repeater and check the SQLi with single quote in User-Agent:
 
 
 
And we got the error.
 
 
Now let’s try to extract the mysql root password
 

Twitter / Hack The Box / CTF Team / Teck_N00bs Community Telegram
Comments