Image Upload Gone Wild: Blind SQLi to Superadmin in Disguise
Discovered blind SQL injection hidden in a filename through file upload, leveraged via second-order logic to escalate privileges to superadmin. Combined creativity, SQL trickery, and business logic abuse to achieve full compromise.