From 02eeeccd33baab95e8b322e54a83992886a45a86 Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Thu, 7 Apr 2011 13:39:36 +0000 Subject: [PATCH] Added UNION query SQL injection tests also with a random number for columns (not only NULL) --- xml/payloads.xml | 246 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 246 insertions(+) diff --git a/xml/payloads.xml b/xml/payloads.xml index 6f844fcc7..8132dca19 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -2341,6 +2341,28 @@ Formats: + + MySQL UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + [COLSTART]-[COLSTOP] + + + + +
+ MySQL +
+
+ MySQL UNION query ([CHAR]) - 1 to 10 columns 3 @@ -2363,6 +2385,28 @@ Formats: + + MySQL UNION query ([CHAR]) - 1 to 10 columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + 1-10 + + + + +
+ MySQL +
+
+ MySQL UNION query ([CHAR]) - 11 to 20 columns 3 @@ -2385,6 +2429,28 @@ Formats: + + MySQL UNION query ([CHAR]) - 11 to 20 columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + 11-20 + + + + +
+ MySQL +
+
+ MySQL UNION query ([CHAR]) - 21 to 30 columns 3 @@ -2407,6 +2473,28 @@ Formats: + + MySQL UNION query ([CHAR]) - 21 to 30 columns + 3 + 4 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + 21-30 + + + + +
+ MySQL +
+
+ MySQL UNION query ([CHAR]) - 31 to 40 columns 3 @@ -2429,6 +2517,28 @@ Formats: + + MySQL UNION query ([CHAR]) - 31 to 40 columns + 3 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + 31-40 + + + + +
+ MySQL +
+
+ MySQL UNION query ([CHAR]) - 41 to 50 columns 3 @@ -2451,6 +2561,28 @@ Formats: + + MySQL UNION query ([CHAR]) - 41 to 50 columns + 3 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + # + [RANDNUM] + 41-50 + + + + +
+ MySQL +
+
+ Generic UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns 3 @@ -2470,6 +2602,25 @@ Formats: + + Generic UNION query ([CHAR]) - [COLSTART] to [COLSTOP] columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + [COLSTART]-[COLSTOP] + + + + + + Generic UNION query ([CHAR]) - 1 to 10 columns 3 @@ -2489,6 +2640,25 @@ Formats: + + Generic UNION query ([CHAR]) - 1 to 10 columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 1-10 + + + + + + Generic UNION query ([CHAR]) - 11 to 20 columns 3 @@ -2508,6 +2678,25 @@ Formats: + + Generic UNION query ([CHAR]) - 11 to 20 columns + 3 + 3 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 11-20 + + + + + + Generic UNION query ([CHAR]) - 21 to 30 columns 3 @@ -2527,6 +2716,25 @@ Formats: + + Generic UNION query ([CHAR]) - 21 to 30 columns + 3 + 4 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 21-30 + + + + + + Generic UNION query ([CHAR]) - 31 to 40 columns 3 @@ -2546,6 +2754,25 @@ Formats: + + Generic UNION query ([CHAR]) - 31 to 40 columns + 3 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 31-40 + + + + + + Generic UNION query ([CHAR]) - 41 to 50 columns 3 @@ -2564,6 +2791,25 @@ Formats: + + + Generic UNION query ([CHAR]) - 41 to 50 columns + 3 + 5 + 1 + 1,2,3,4,5 + 1 + [UNION] + + + -- + [RANDNUM] + 41-50 + + + + +