fg0x0's notes
Ctrlk
  • ๐Ÿ‘€Introduction
    • ๐Ÿดโ€โ˜ ๏ธAbout me
  • ๐Ÿ‘พoffensive-security
    • ๐ŸฒOSCP
    • โ›“๏ธOSEP
    • ๐Ÿ•ธ๏ธOSWE
    • ๐ŸŒŒPG-Practice
  • ๐ŸšฉRed Team
    • โ˜ข๏ธActive Directory Exploitation
    • ๐Ÿ‘ฟRed Teaming Zero to Hero
    • ๐Ÿ‘ฟRed Teaming All The Things
    • ๐Ÿ•ธ๏ธWeb Exploitation
    • ๐Ÿ’€Binary Exploitation
    • โ˜ ๏ธExploit Development
  • ๐Ÿณ๏ธBlue Team
    • ๐Ÿ”Digital Forensics
    • ๐Ÿ”Cryptography & Math
    • โชReverse Engineering
  • ๐Ÿดโ€โ˜ ๏ธctf
    • ๐Ÿ‡Haruul Zangi
    • ๐Ÿดโ€โ˜ ๏ธOther CTF
  • ๐ŸงŠHackTheBox
    • ๐ŸชŸWindows Machine
    • ๐ŸงLinux Machine
    • โ˜ ๏ธOther Platform Machines
    • Web Exploitation
      • ๐Ÿ‘ฝFlask SSTI
      • Injection
        • ๐Ÿ‘ฝPhonebook ( LDAP Injection )
        • sanitize ( SQL Injection )
        • Weather app ( SQL Injection )
        • Intergalactic Post ( php filter SQLi )
        • C.O.P ( SQL injection + Revshell )
      • ๐Ÿ’ฅPrototype Pollution
      • ๐Ÿ˜ตโ€๐Ÿ’ซinsecure deserialization
      • XSS
      • ๐Ÿ‘พSymfony
      • ๐Ÿ‘ฅXXE
      • Ping submit hiideg
      • RCE
      • LFI
      • File Upload
      • URL submit hiideg
      • Invoice ilgeedeg
      • HTTP2 smuggling
    • Forensics
  • ๐Ÿ’€Synack Red Team
Powered by GitBook
On this page
  1. ๐ŸงŠHackTheBox
  2. Web Exploitation
  3. Injection

Weather app ( SQL Injection )

Logoweather appโ€Šโ€”โ€Šhtb walkthrough (CVE 2018โ€“12116 ssrf via request splitting)Medium
LogoHackTheBox Weather AppMedium
Previoussanitize ( SQL Injection )NextIntergalactic Post ( php filter SQLi )

Last updated 1 year ago