SQL Injection
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
How to start
Study SQL
Methodology
Time Based SQLi Payloads
Top SQLI reports from HackerOne:
SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database to Starbucks - 743 upvotes, $0
SQL injection in https://labs.data.gov/dashboard/datagov/csv_to_json via User-agent to GSA Bounty - 671 upvotes, $0
Time-Based SQL injection at city-mobil.ru to Mail.ru - 625 upvotes, $15000
SQL injection at https://sea-web.gold.razer.com/ajax-get-status.php via txid parameter to Razer - 580 upvotes, $2000
SQL Injection in https://api-my.pay.razer.com/inviteFriend/getInviteHistoryLog to Razer - 528 upvotes, $2000
Blind SQL Injection to InnoGames - 432 upvotes, $2000
SQL injection at fleet.city-mobil.ru to Mail.ru - 370 upvotes, $10000
SQL Injection in report_xml.php through countryFilter[] parameter to Valve - 348 upvotes, $25000
[windows10.hi-tech.mail.ru] Blind SQL Injection to Mail.ru - 329 upvotes, $5000
SQL Injection on cookie parameter to MTN Group - 303 upvotes, $0
[www.zomato.com] SQLi - /php/โโโโโโโโโโ - item_id to Zomato - 289 upvotes, $4500
SQL Injection at https://sea-web.gold.razer.com/lab/cash-card-incomplete-translog-resend via period-hour Parameter to Razer - 240 upvotes, $2000
[api.easy2pay.co] SQL Injection at fortumo via TransID parameter [Bypassing Signature Validation๐ฅ] to Razer - 232 upvotes, $4000
Boolean-based SQL Injection on relap.io to Mail.ru - 227 upvotes, $0
Blind SQL Injection in city-mobil.ru domain to Mail.ru - 224 upvotes, $2000
SQL Injection in agent-manager to Acronis - 223 upvotes, $0
Blind SQLi leading to RCE, from Unauthenticated access to a test API Webservice to Starbucks - 218 upvotes, $0
SQL Injection in www.hyperpure.com to Zomato - 211 upvotes, $2000
Blind SQL Injection on starbucks.com.gt and WAF Bypass :* to Starbucks - 202 upvotes, $0
Remote Code Execution on contactws.contact-sys.com via SQL injection in TCertObject operation "Delete" to QIWI - 194 upvotes, $0
SQLi at https://sea-web.gold.razer.com/demo-th/purchase-result.php via orderid Parameter to Razer - 183 upvotes, $2000
Blind SQL injection in Hall of Fap to Pornhub - 179 upvotes, $0
www.drivegrab.com SQL injection to Grab - 175 upvotes, $4500
Sql injection on docs.atavist.com to Automattic - 158 upvotes, $0
SQL Injection [unauthenticated] with direct output at https://news.mail.ru/ to Mail.ru - 155 upvotes, $7500
bypass sql injection #1109311 to Acronis - 150 upvotes, $0
SQL injection in GraphQL endpoint through embedded_submission_form_uuid parameter to HackerOne - 147 upvotes, $0
SQL Injection Union Based to Automattic - 123 upvotes, $0
Last updated
Was this helpful?