A UNION SELECT appends attacker-chosen rows to a returned result. PostgreSQL adds one wrinkle over MySQL: its type system is strict, so each column in the appended SELECT must match the original column's type or be cast explicitly. Casting everything to text with ::text (or selecting NULL, which fits any type) sidesteps type mismatches.
The flow is the same as elsewhere: detect the column count, find a reflected text column, then read the catalog and data through it. PostgreSQL exposes schema information in both the SQL-standard information_schema and the native pg_catalog, and string_agg() is its equivalent of GROUP_CONCAT for collapsing many rows into one cell.
' UNION SELECT NULL,string_agg(table_name,','),NULL FROM information_schema.tables WHERE table_schema='public'--
Pages#
- Detect column count:
ORDER BYandUNION SELECT NULLprobing, with casts. - Extract schema and data: enumerate and dump via
information_schemaandpg_catalog.
References#
- PostgreSQL Documentation: UNION, type casts,
string_agg - OWASP Testing Guide: Testing for SQL Injection