Web Hack List

Collected research

Prepared Statements? Prepared to Be Vulnerable.

The Node.js mysql and mysql2 drivers convert JavaScript objects and arrays into SQL fragments by default, so submitting a JSON object where a string is expected turns a correctly parameterised prepared statement into attacker-controlled SQL. It enables mass reads, updates and deletes, and in the reported case a password-reset bypass and account takeover.

Record

Researcher
Balazs Bucsay
Published by
blog.mantrainfosec.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Balazs Bucsay, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .