MediumWeb Security

SQLi: Checkout Bypass

250 pointsEst. 45 min11,230 solved00:00 elapsed

Mission Briefing

An e-commerce staging site lets you manipulate the checkout total. Find the injection point and prove full database access.

Objectives

  • Identify the vulnerable parameter
  • Extract the database schema
  • Dump the admin credentials table
  • Bypass checkout authorization

Terminal Simulation

root@infoenc-range: ~
Infoenc Range v2.4 — target session established
Target: 10.10.14.22 | Type 'help' for available commands
$

Submit Flag

Hint: try cat flag.txt in the terminal above.

Hints

Skills Practiced

SQL InjectionBurp SuiteManual Testing

Scoreboard

Base points250
Hint penalty-0
Net score250