
SQL injection to root on a 2013 lab box
Chaining a login-form SQL injection through sqlmap’s –os-shell into a Linux 2.6.32 local root exploit to go from the ’nobody’ user to full control of the server.

Chaining a login-form SQL injection through sqlmap’s –os-shell into a Linux 2.6.32 local root exploit to go from the ’nobody’ user to full control of the server.