Blind SQL injection in an HTTP header leading to command execution
Time-based blind SQL injection in the X-Forwarded-For proxy header. The value reached the query without parameterisation, allowing stacked statements. The database user held administrative privileges: the chain reached the stored procedures that run operating-system commands.
A route open to command execution on the database server and to the databases hosted on it. The chain was verified up to the step before impact.