MediumWeb Security
SQLi: Checkout Bypass
250 pointsEst. 45 min11,230 solved00:00 elapsed
Mission Briefing
An e-commerce staging site lets you manipulate the checkout total. Find the injection point and prove full database access.
Objectives
- Identify the vulnerable parameter
- Extract the database schema
- Dump the admin credentials table
- Bypass checkout authorization
Terminal Simulation
root@infoenc-range: ~
Infoenc Range v2.4 — target session established
Target: 10.10.14.22 | Type 'help' for available commands
$
Submit Flag
Hint: try cat flag.txt in the terminal above.
Hints
Skills Practiced
SQL InjectionBurp SuiteManual Testing
Scoreboard
Base points250
Hint penalty-0
Net score250