PostgreSQL

Database commands

Comments

SELECT 1; –comment
SELECT /*comment*/1;

Version

SELECT version();

Users

SELECT user;
SELECT current_user;
SELECT session_user;
SELECT usename FROM pg_user WHERE usesuper IS TRUE
SELECT usename FROM pg_user;
SELECT getpgusername();
SELECT usename FROM pg_user
CREATE USER <name> PASSWORD '<pass>';
CREATE USER <name> PASSWORD '<pass>′ CREATEUSER;
DROP USER <name>;
ALTER USER <name> CREATEUSER CREATEDB;

Privileges

Database info

List tables

List columns

Filter table by column name

Access nth row

String operations

Conditional execution

Time delay

DNS and HTTP

Passwords

Format: MD5

Vulnerabilities

RCE

Arbitrary file access

SQLi

Arbitrary file write

Last updated