2 ms·
Sending arbitrary SQL for remote execution feels very much like a remote shell, and can quickly turn into one with a misconfigured or buggy extension.
by ComodoHacker 5y ago
Sending arbitrary SQL for remote execution feels very much like a remote shell, and can quickly turn into one with a misconfigured or buggy extension.
- mano78 5y agoNot much different than a remote invocation of any other database (ok, this is more "tool-friendly" so it may open up to more attacks). But your point stands.