MySQL
Database commands
Comments
SELECT 1; #comment
SELECT /*comment*/1;Version
SELECT @@versionUsers
SELECT user();
SELECT system_user();
SELECT user FROM mysql.user; -- priv
CREATE USER <name> IDENTIFIED BY '<pass>';
DROP USER <name>;
GRANT ALL PRIVILEGES ON *.* TO <name>@'%';
SELECT grantee, privilege_type, is_grantable FROM information_schema.user_privileges WHERE privilege_type = 'SUPER';
SELECT host, user FROM mysql.user WHERE Super_priv = 'Y';Privileges
Database info
List tables
List columns
Filter table by column name
Access nth row
String operations
Conditional execution
Time delay
Hostname
Passwords
Vulnerabilities
Arbitrary file access
Arbitrary file write
Local code execution (raptor_udf)
Last updated