#SQLi
CVE-2024-12727 Sophos coming in with an unauthenticated SQLi in their firewall appliance 👏
CVE-2023-34990 🤦‍♂️🤦‍♂️
December 22, 2024 at 8:43 AM
Looks like I'm not the only one who found a twexit SQLi vuln 😬
December 22, 2023 at 8:57 AM
You should know that while you were asleep, one new XSS vuln, and two new SQLi vulns were found.
December 22, 2023 at 10:17 AM
This is such awesome feedback to get! Always nice to hear when something I made helped people out. 🥰

Cheatsheet is here: tib3rius.com/sqli
March 25, 2025 at 3:18 AM
Maybe they are though. Twexit fan updated their bio to read “8 sqli (these numbers are counting non-twexit Adrianus sites)” 💀
December 26, 2023 at 5:49 AM
Found a time-based SQLi on gori.gov.ge.
December 8, 2024 at 4:16 PM
Not your typical SQLi vector... 😈
November 9, 2023 at 1:49 AM
Ronin vulns: A Ruby library that tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.

github.com/ronin-rb/ron...

#infosec
#cybersecurity
#threatdetection
#xss #SQLi
GitHub - ronin-rb/ronin-vulns: Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), an...
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects. - ronin-rb...
github.com
November 19, 2024 at 3:53 AM
Added the "safe" OR-based payloads to my SQL injection cheatsheet: #sa...us.com/sqli#safe-or-based-payloads" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">tib3rius.com/sqli#sa...

Video explanation here if you missed it: youtu.be/EpCA4HF-aUM

Still looking for an MSSQL one or a more reliable SQLite one, if anyone wants to help out. 👀
November 15, 2024 at 12:00 PM
By the way, this isn't just twexit and mastochist. Every single website that Adrianus has ever made is vulnerable to SQLi.
December 26, 2023 at 7:25 AM
And folks say SQLi is dead 😏
CVE-2024-12727 Sophos coming in with an unauthenticated SQLi in their firewall appliance 👏
CVE-2023-34990 🤦‍♂️🤦‍♂️
December 23, 2024 at 2:32 AM
ServiceNow AI flaws: unauth SQLi = arbitrary SQL on the instance DB. Two 9.3 criticals. Patch self-hosted now. https://intel.threadlinqs.com/threat/TL-2026-2653 #ThreatIntel #CVE_2026_13016 #CVE_2026_86857 #ServiceNow
September 25, 2026 at 12:55 PM
:( all of shreyan's websites have SQLi
December 14, 2023 at 12:50 AM
also if we're still doing SQLi in the fucking TWENTY THIRD CENTURY we deserve to fucking perish
"the probe used multiple sql injections" fjdl;askjklasdfjklasd; trek decides to try to sound like real tech ew
July 6, 2024 at 3:05 PM
Last month I breached a bank with Spring2026!. Today I found SQLi on a login portal for a financial company. It feels like 2016 ❤️
May 26, 2026 at 9:55 PM
【セキュリティ ニュース】「ServiceNow AI Platform」にSQLiなど複数脆弱性 - 修正版を提供(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/190682
September 25, 2026 at 8:15 AM
Steht SQLi für Structured Querry Language injection? 💉
February 5, 2024 at 11:50 AM
Rhino Security has found 6 vulns in the Infoblox NetMRI network automation and configuration management solution.

Bugs include an auth bypass via hardcoded credentials, privlege escalation via cookie forgery, an unauth command injection, and an SQLi

Quite bad

rhinosecuritylabs.com/research/inf...
Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities
While performing research on Infoblox's NetMRI network automation and configuration management solution, we discovered 5 vulnerabilities.
rhinosecuritylabs.com
June 5, 2025 at 12:05 PM
Hoi #infosec people, afayk are SQLi attacks still a thing in the wild?
February 7, 2025 at 4:55 PM
SQLi *and* a LFI today.
All of your files are belong to me 💁🏻‍♀️
This box is just riddled with all kinds of holes. Love it. 👏🏻

#hacker #SQLi #LFI #HTB #infosec #cybersecurity
December 4, 2024 at 9:39 PM
FunnelKit: 23 CVEs, max CVSS 9.8, 100% unpatched, trust score D. SQLi and XSS dominate. Patch discipline is failing. https://www.valtersit.com/vendors/funnelkit/ #cybersecurity #infosec #WordPress
Funnelkit
www.valtersit.com
September 25, 2026 at 3:00 AM
Stará dobrá SQLi 🤦
March 12, 2026 at 2:20 PM
oh i’ll have to look if they ever update the “your id” here, but this is what was used years ago to steal peoples sessions on uh…..damn what was the site everyone used for checking blocks before clearsky? php application that also had a bunch of sqli problems lol
January 8, 2026 at 6:56 PM
bugbountyhunting.com

Bugbounty write ups search engine. A large collection of articles with examples of finding different types of vulnerabilities: XSS, SSRF, SQLI, RCE, IDOR.

Creator twitter.com/payloadartist

#pentest #cybersecurity
November 5, 2023 at 11:28 PM