Loading HuntDB...

Blind User-Agent SQL Injection to Blind Remote OS Command Execution at █████████

Critical
S
Sony
Submitted None

Team Summary

Official summary from Sony

The researcher reported that a login form of a Sony website was vulnerable to a blind SQL injection. The researcher was able to use the blind SQL injection to enable xp_cmdshell functionality on the database and then run system commands. The output from the system commands was then obtained via DNS-based exfiltration.

Reported by echidonut

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

OS Command Injection