← Back to list

SQL Injection 2 — Portswigger

Lab2

Rukminikanthan Sarangan · 2024-04-27 14:56 · 0 claps · 1.3 min read
#sql-injection #portswigger #lab-2
Open on Medium ↗

SQL Injection 2 — Portswigger

Lab2

SQL injection vulnerability allowing login bypass

  • First we accessed the lab
  • Then we clicked “my account” .
  • As given below we tried single quotation as username to check if sql injection is possible in this scenario.

  • For this we get the internal error as below

  • As we now know this vulnerability, we tried administrator’ — — to get into the administrator account by force commenting the password .

  • After this we got into the administrator account and solved the lab.

Have a good day ;)


메타데이터
post_id
01839912cbca
slug
sql-injection-2-portswigger-01839912cbca
url
https://medium.com/@vrsarangan01/sql-injection-2-portswigger-01839912cbca
canonical_url
https://medium.com/@vrsarangan01/sql-injection-2-portswigger-01839912cbca
author_url
https://medium.com/@vrsarangan01
status
ok
fetched_at
2026-07-23 23:41:22