diff --git a/data/xml/payloads/union_query.xml b/data/xml/payloads/union_query.xml index 9513892fa..578b3d2a2 100644 --- a/data/xml/payloads/union_query.xml +++ b/data/xml/payloads/union_query.xml @@ -1,7 +1,10 @@ - - + + + + + Generic UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns (custom) 6 @@ -59,6 +62,7 @@ + Generic UNION query ([CHAR]) - 1 to 10 columns 6 @@ -116,6 +120,7 @@ + Generic UNION query ([CHAR]) - 11 to 20 columns 6 @@ -173,6 +178,7 @@ + Generic UNION query ([CHAR]) - 21 to 30 columns 6 @@ -230,6 +236,7 @@ + Generic UNION query ([CHAR]) - 31 to 40 columns 6 @@ -287,6 +294,7 @@ + Generic UNION query ([CHAR]) - 41 to 50 columns 6 @@ -305,6 +313,7 @@ + Generic UNION query (NULL) - 41 to 50 columns 6 @@ -343,6 +352,9 @@ + + + MySQL UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns (custom) 6 @@ -409,6 +421,7 @@ + MySQL UNION query ([CHAR]) - 1 to 10 columns 6 @@ -475,6 +488,7 @@ + MySQL UNION query ([CHAR]) - 11 to 20 columns 6 @@ -541,6 +555,7 @@ + MySQL UNION query ([CHAR]) - 21 to 30 columns 6 @@ -607,6 +622,7 @@ + MySQL UNION query ([CHAR]) - 31 to 40 columns 6 @@ -673,6 +689,7 @@ + MySQL UNION query ([CHAR]) - 41 to 50 columns 6 @@ -738,5 +755,473 @@ MySQL + + + + + + PostgreSQL UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + [COLSTART]-[COLSTOP] + + + + +
+ PostgreSQL +
+
+ + + PostgreSQL UNION query (NULL) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + [COLSTART]-[COLSTOP] + + + + +
+ PostgreSQL +
+
+ + + PostgreSQL UNION query ([RANDNUM]) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + [COLSTART]-[COLSTOP] + + + + +
+ PostgreSQL +
+
+ + + + PostgreSQL UNION query ([CHAR]) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + 1-10 + + + + +
+ PostgreSQL +
+
+ + + PostgreSQL UNION query (NULL) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + 1-10 + + + + +
+ PostgreSQL +
+
+ + + PostgreSQL UNION query ([RANDNUM]) - 1 to 10 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 1-10 + + + + +
+ PostgreSQL +
+
+ + + + PostgreSQL UNION query ([CHAR]) - 11 to 20 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + 11-20 + + + + +
+ PostgreSQL +
+
+ + + PostgreSQL UNION query (NULL) - 11 to 20 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + 11-20 + + + + +
+ PostgreSQL +
+
+ + + + + + Microsoft SQL Server UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + [COLSTART]-[COLSTOP] + + + + +
+ Microsoft SQL Server +
+
+ + + Microsoft SQL Server UNION query (NULL) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + [COLSTART]-[COLSTOP] + + + + +
+ Microsoft SQL Server +
+
+ + + + Microsoft SQL Server UNION query ([CHAR]) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + 1-10 + + + + +
+ Microsoft SQL Server +
+
+ + + Microsoft SQL Server UNION query (NULL) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + 1-10 + + + + +
+ Microsoft SQL Server +
+
+ + + + + + Oracle UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns (custom) + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [CHAR] + [COLSTART]-[COLSTOP] + + + + +
+ Oracle +
+
+ + + + Oracle UNION query (NULL) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + NULL + 1-10 + + + + +
+ Oracle +
+
+ + + + + + Generic UNION ALL query ([CHAR]) - 1 to 10 columns + 6 + 2 + 1 + 1,2,3,4,5 + 1 + [UNION ALL] + + + [GENERIC_SQL_COMMENT] + [CHAR] + 1-10 + + + + + + + + + MySQL inline comment UNION ([CHAR]) - 1 to 10 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + /*!50000UNION*/ /*!50000SELECT*/ + + + # + [CHAR] + 1-10 + + + + +
+ MySQL +
+
+ + + + Generic UNION with whitespace obfuscation ([CHAR]) - 1 to 10 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + %0aUNION%0aSELECT%0a + + + [GENERIC_SQL_COMMENT] + [CHAR] + 1-10 + + + + + + + + + Stacked query UNION attempt ([CHAR]) - 1 to 10 columns + 6 + 4 + 2 + 1,2,3,4,5 + 1 + ;[UNION] + + + [GENERIC_SQL_COMMENT] + [CHAR] + 1-10 + + + + + + + + + HEX encoded UNION query (0x[HEX]) - 1 to 10 columns + 6 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + [GENERIC_SQL_COMMENT] + 0x[HEX] + 1-10 + + + + + + + + + Generic UNION query ([CHAR]) - 51 to 60 columns + 6 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + [GENERIC_SQL_COMMENT] + [CHAR] + 51-60 + + + + + + + + Generic UNION query (NULL) - 51 to 60 columns + 6 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + [GENERIC_SQL_COMMENT] + NULL + 51-60 + + + + + + + +