Web Hack List

Preliminary research

SELECT-only PostgreSQL exploitation: Drupal case study

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Develops a SELECT-only Drupal/PostgreSQL injection into large-object file writes, configuration replacement and native module loading in a new backend. The writeup explains database privileges, connection-pool lifecycle and module ABI requirements, showing why configuration reload alone does not immediately execute code in an existing session.

Record

Researcher
N. Maccary
Published by
Lexfo / Ambionics

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of N. Maccary, first published at the original source. Preserved copies are kept so the citation survives its host.