githubEdit

SQL Injection

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

How to start

  1. Study SQL

Methodology

Time Based SQLi Payloads

Top SQLI reports from HackerOne:

  1. Blind SQL Injection arrow-up-rightto InnoGames - 432 upvotes, $2000

  2. Sql injection on docs.atavist.comarrow-up-right to Automattic - 158 upvotes, $0

  3. bypass sql injection #1109311arrow-up-right to Acronis - 150 upvotes, $0

  4. SQL Injection Union Basedarrow-up-right to Automattic - 123 upvotes, $0

Last updated