Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE (opens in new tab)
Turning a SELECT-only PostgreSQL SQL injection into remote command execution when the injected role is a PostgreSQL superuser.
Read the original articleTurning a SELECT-only PostgreSQL SQL injection into remote command execution when the injected role is a PostgreSQL superuser.
Read the original article