This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "SQL Injection Cookbook template"
From OWASP
m (→Queries) |
|||
Line 44: | Line 44: | ||
=Queries= | =Queries= | ||
− | ==Strings | + | ==Strings== |
===Valid string delimiters=== | ===Valid string delimiters=== | ||
===String concatenation=== | ===String concatenation=== |
Revision as of 06:42, 14 January 2007
[hide]
Database objects
Tables
List table names
Create a table
List columns for a specific table
View table permissions
Change table permissions
Stored procedures or functions
List stored procedures or functions
Parameters for a stored procedure or function
Source code of a stored procedure or function
Create a stored procedure or function
System data
Users
Identify current user
List of database users
List of database administrators
Database user permissions
Create a new user
Change a user password
Delete a user
Database server
View database server settings
Change database server settings
View database server processes
Kill database server process
Host Operating System
Operating System version
OS environment variables
Execute OS shell commands
Read file contents
Arbitrary file writes
File uploads
Unique database platform features
Queries
Strings
Valid string delimiters
String concatenation
String-based queries with no quote characters
Query syntax
Acceptable whitespace
Tableless queries
Query comments
Query command delimiters
Set operators
Set operators are used to combine the results from two different queries. The number of columns and order of column types must be identical for both queries. The general syntax is
SELECT
fname, lname
FROM
employees
SET_OPERATOR
SELECT
fname, lname
FROM
customers