• Detection

  • Auth Bypass

  • Column Enum

  • Union to get all data

  • Extract data through union

  • Code execution

  • Reverse shell

  • Reference

  • For oracle injection https://www.securityidiots.com/Web-Pentest/SQL-Injection/Union-based-Oracle-Injection.html

  • https://book.hacktricks.xyz/pentesting-web/sql-injection

  • CHeatsheet

    • https://pentestmonkey.net/category/cheat-sheet/sql-injection