This is an explanation of the Web Exploitation challenge "Web Gauntlet 2" from the CyLab Security Academy (formerly picoCTF).
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before ...
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. The attack was discovered by ...
Immortalized by “Little Bobby Drop Tables” in XKCD 327, SQL injection (SQLi) was first discovered in 1998, yet continues to plague web applications across the internet. Even the OWASP Top Ten lists ...
WordPress backup plugin vulnerability CVE-2026-19949 in All-in-One WP Migration exposes 3.25 million unpatched sites to unauthenticated remote code execution, with a weaponized proof-of-concept ...
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.