{keyword} Union All Select Null,null,null,null,null,null-- Gojb -

: The attacker wants the database to return the results of the original query plus the results of their injected query.

: A website takes user input and places it directly into a SQL query without "cleaning" it first. : The attacker wants the database to return

: NULL is used because it is compatible with almost any data type (integers, strings, dates, etc.). This string is a classic example of a

This string is a classic example of a used by security researchers and attackers to probe a website's database for vulnerabilities. -- (The Comment) In SQL, double-dashes signify the

If the page returns an error (like "The used SELECT statements have a different number of columns"), the attacker will try again with five or seven NULL values until the error disappears. 4. -- (The Comment) In SQL, double-dashes signify the start of a comment.

Related Articles

Back to top button