14 August, 2026 - 05:16 PM
(07 August, 2026 - 11:45 PM)Waterloo1337 Wrote: Show MoreDbsbdbbscPanel has a SQL injection in its database rename feature that lets any authenticated hosting customer execute arbitrary SQL as the database root user. That's right, the $5/month shared hosting account on a server with 500+ websites can read, modify, or delete every database on the entire server.
But it gets better. Depending on how MySQL/MariaDB is configured, the root SQL context escalates all the way to OS-level command execution. cPanel's own advisory warns this "may extend to operating-system-level compromise."
Attack Flow:
Like for More Exploits
![[Image: w-E1ikg-U.gif]](https://i.ibb.co/d4Z9f3X6/w-E1ikg-U.gif)