Union-based

When an injectable query returns its rows to the page, a UNION SELECT lets you append rows of your own choosing. The appended SELECT runs with the application's privileges and its columns appear wherever the original result is displayed, which turns a data-returning query into a general read primitive over everything the database account can reach.

Two conditions must hold. The injected SELECT has to project the same number of columns as the original query, and the columns you want to read must sit in positions whose types are compatible with what the page renders (usually a string column). NULL is type-compatible with everything, so it is the safe filler while you work out the layout.

The workflow is: detect the column count, find which columns are reflected, then read schema and data through those positions. MySQL's information_schema supplies the schema, and GROUP_CONCAT() collapses many rows into one so a single reflected cell can carry a whole table.

Pages#

References#

  • MySQL Reference Manual: UNION clause and information_schema
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more