Union-based

A UNION SELECT appends attacker-chosen rows to a returned result. PostgreSQL adds one wrinkle over MySQL: its type system is strict, so each column in the appended SELECT must match the original column's type or be cast explicitly. Casting everything to text with ::text (or selecting NULL, which fits any type) sidesteps type mismatches.

The flow is the same as elsewhere: detect the column count, find a reflected text column, then read the catalog and data through it. PostgreSQL exposes schema information in both the SQL-standard information_schema and the native pg_catalog, and string_agg() is its equivalent of GROUP_CONCAT for collapsing many rows into one cell.

sql
' UNION SELECT NULL,string_agg(table_name,','),NULL FROM information_schema.tables WHERE table_schema='public'-- 

Pages#

References#

  • PostgreSQL Documentation: UNION, type casts, string_agg
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more