SQL Injection

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

How to start

  1. Study SQL

Methodology

Time Based SQLi Payloads

Top SQLI reports from HackerOne:

  1. Time-Based SQL injection at city-mobil.ru to Mail.ru - 625 upvotes, $15000

  2. Blind SQL Injection to InnoGames - 432 upvotes, $2000

  3. SQL injection at fleet.city-mobil.ru to Mail.ru - 370 upvotes, $10000

  4. SQL Injection on cookie parameter to MTN Group - 303 upvotes, $0

  5. Boolean-based SQL Injection on relap.io to Mail.ru - 227 upvotes, $0

  6. Blind SQL Injection in city-mobil.ru domain to Mail.ru - 224 upvotes, $2000

  7. SQL Injection in agent-manager to Acronis - 223 upvotes, $0

  8. SQL Injection in www.hyperpure.com to Zomato - 211 upvotes, $2000

  9. Blind SQL injection in Hall of Fap to Pornhub - 179 upvotes, $0

  10. www.drivegrab.com SQL injection to Grab - 175 upvotes, $4500

  11. Sql injection on docs.atavist.com to Automattic - 158 upvotes, $0

  12. bypass sql injection #1109311 to Acronis - 150 upvotes, $0

  13. SQL Injection Union Based to Automattic - 123 upvotes, $0

Last updated

Was this helpful?