Collected research
AWS WAF Clients Left Vulnerable to SQL Injection Due to Unorthodox MSSQL Design Choice
MSSQL accepts stacked statements with no semicolon and no whitespace between them, which AWS WAF's SQL parser treated as invalid and let through. Appending an exec() payload to an injectable parameter bypassed the WAF for UNION-based login bypass, password rewrites and enabling xp_cmdshell for remote code execution. Microsoft called the parsing by design; AWS fixed the WAF.
Record
- Researcher
- Marc Olivier Bergeron and @GoSecure_Inc
- Published by
- GoSecure
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Marc Olivier Bergeron and @GoSecure_Inc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .