Hacker News new | past | comments | ask | show | jobs | submit login

That requires your application to be vulnerable to two types of exploit in order to pull off RCE - if you are vulnerable to SQLi there are likely a whole raft of other issues which would give you a remote shell.

As a standalone issue I agree with the GP comment - this bug is not a RCE issue, it's privilege escalation.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: