SQL Server readily executes stacked queries: a ;-separated second statement usually runs, and many T-SQL drivers (including common ADO.NET and PHP sqlsrv usage) allow it. This turns a read-only-looking injection into arbitrary statement execution, which is what makes the strongest MSSQL primitives reachable.
Append a statement that acts:
'; UPDATE users SET is_admin=1 WHERE username='attacker'--
'; EXEC xp_cmdshell 'whoami'--
Stacking is what enables EXEC of stored and extended procedures, the sp_configure/RECONFIGURE pair that re-enables xp_cmdshell, WAITFOR timing, and DDL. Dynamic SQL via EXEC() or sp_executesql can also be chained, which helps assemble commands from extracted values (building a UNC path for out-of-band, for example).
Availability still depends on the driver and API: a parameterized call that sends one statement rejects the second. Confirm stacking by observing a side effect (a changed row, a created object) rather than assuming it. When it is blocked, fall back to in-query techniques (union, error, blind, error-based) that complete within the single original statement.
References#
- Microsoft SQL Server Documentation: batches, EXECUTE, sp_executesql
- OWASP Testing Guide: Testing for SQL Injection