Blind User-Agent SQL Injection to Blind Remote OS Command Execution at █████████
Critical
S
Sony
Submitted None
Team Summary
Official summary from Sony
The researcher reported that a login form of a Sony website was vulnerable to a blind SQL injection. The researcher was able to use the blind SQL injection to enable xp_cmdshell functionality on the database and then run system commands. The output from the system commands was then obtained via DNS-based exfiltration.
Actions:
Reported by
echidonut
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
OS Command Injection