You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: xml/boundaries.xml
+43-44Lines changed: 43 additions & 44 deletions
Original file line number
Diff line number
Diff line change
@@ -31,6 +31,7 @@ Tag: <boundary>
31
31
6: TOP
32
32
7: Table name
33
33
8: Column name
34
+
9: Pre-WHERE (non-query)
34
35
35
36
A comma separated list of these values is also possible.
36
37
@@ -422,7 +423,7 @@ Formats:
422
423
<!-- Pre-WHERE generic boundaries (e.g. "UPDATE table SET '$_REQUEST["name"]' WHERE id=1" or "INSERT INTO table VALUES('$_REQUEST["value"]') WHERE id=1)"-->
423
424
<boundary>
424
425
<level>5</level>
425
-
<clause>1</clause>
426
+
<clause>9</clause>
426
427
<where>1,2</where>
427
428
<ptype>2</ptype>
428
429
<prefix>') WHERE [RANDNUM]=[RANDNUM]</prefix>
@@ -431,7 +432,7 @@ Formats:
431
432
432
433
<boundary>
433
434
<level>5</level>
434
-
<clause>1</clause>
435
+
<clause>9</clause>
435
436
<where>1,2</where>
436
437
<ptype>2</ptype>
437
438
<prefix>") WHERE [RANDNUM]=[RANDNUM]</prefix>
@@ -440,7 +441,7 @@ Formats:
440
441
441
442
<boundary>
442
443
<level>4</level>
443
-
<clause>1</clause>
444
+
<clause>9</clause>
444
445
<where>1,2</where>
445
446
<ptype>1</ptype>
446
447
<prefix>) WHERE [RANDNUM]=[RANDNUM]</prefix>
@@ -449,7 +450,7 @@ Formats:
449
450
450
451
<boundary>
451
452
<level>4</level>
452
-
<clause>1</clause>
453
+
<clause>9</clause>
453
454
<where>1,2</where>
454
455
<ptype>2</ptype>
455
456
<prefix>' WHERE [RANDNUM]=[RANDNUM]</prefix>
@@ -458,7 +459,7 @@ Formats:
458
459
459
460
<boundary>
460
461
<level>5</level>
461
-
<clause>1</clause>
462
+
<clause>9</clause>
462
463
<where>1,2</where>
463
464
<ptype>4</ptype>
464
465
<prefix>" WHERE [RANDNUM]=[RANDNUM]</prefix>
@@ -467,12 +468,48 @@ Formats:
467
468
468
469
<boundary>
469
470
<level>4</level>
470
-
<clause>1</clause>
471
+
<clause>9</clause>
471
472
<where>1,2</where>
472
473
<ptype>1</ptype>
473
474
<prefix> WHERE [RANDNUM]=[RANDNUM]</prefix>
474
475
<suffix>[GENERIC_SQL_COMMENT]</suffix>
475
476
</boundary>
477
+
478
+
<boundary>
479
+
<level>5</level>
480
+
<clause>9</clause>
481
+
<where>1</where>
482
+
<ptype>2</ptype>
483
+
<prefix>'||(SELECT '[RANDSTR]' FROM DUAL WHERE [RANDNUM]=[RANDNUM]</prefix>
484
+
<suffix>)||'</suffix>
485
+
</boundary>
486
+
487
+
<boundary>
488
+
<level>5</level>
489
+
<clause>9</clause>
490
+
<where>1</where>
491
+
<ptype>2</ptype>
492
+
<prefix>'||(SELECT '[RANDSTR]' WHERE [RANDNUM]=[RANDNUM]</prefix>
493
+
<suffix>)||'</suffix>
494
+
</boundary>
495
+
496
+
<boundary>
497
+
<level>5</level>
498
+
<clause>9</clause>
499
+
<where>1</where>
500
+
<ptype>1</ptype>
501
+
<prefix>'+(SELECT [RANDSTR] WHERE [RANDNUM]=[RANDNUM]</prefix>
502
+
<suffix>)+'</suffix>
503
+
</boundary>
504
+
505
+
<boundary>
506
+
<level>5</level>
507
+
<clause>9</clause>
508
+
<where>1</where>
509
+
<ptype>2</ptype>
510
+
<prefix>'+(SELECT '[RANDSTR]' WHERE [RANDNUM]=[RANDNUM]</prefix>
511
+
<suffix>)+'</suffix>
512
+
</boundary>
476
513
<!-- End of pre-WHERE generic boundaries -->
477
514
478
515
<!-- Pre-WHERE derived table boundaries - e.g. "SELECT * FROM (SELECT column FROM table WHERE column LIKE '%$_REQUEST["name"]%') AS t1"-->
@@ -549,44 +586,6 @@ Formats:
549
586
</boundary>
550
587
<!-- End of pre-WHERE derived table boundaries -->
551
588
552
-
<!-- INSERT/UPDATE generic boundaries (e.g. "INSERT INTO table VALUES ('$_REQUEST["name"]',...)"-->
553
-
<boundary>
554
-
<level>5</level>
555
-
<clause>1</clause>
556
-
<where>1</where>
557
-
<ptype>2</ptype>
558
-
<prefix>'||(SELECT '[RANDSTR]' FROM DUAL WHERE [RANDNUM]=[RANDNUM]</prefix>
559
-
<suffix>)||'</suffix>
560
-
</boundary>
561
-
562
-
<boundary>
563
-
<level>5</level>
564
-
<clause>1</clause>
565
-
<where>1</where>
566
-
<ptype>2</ptype>
567
-
<prefix>'||(SELECT '[RANDSTR]' WHERE [RANDNUM]=[RANDNUM]</prefix>
568
-
<suffix>)||'</suffix>
569
-
</boundary>
570
-
571
-
<boundary>
572
-
<level>5</level>
573
-
<clause>1</clause>
574
-
<where>1</where>
575
-
<ptype>1</ptype>
576
-
<prefix>'+(SELECT [RANDSTR] WHERE [RANDNUM]=[RANDNUM]</prefix>
577
-
<suffix>)+'</suffix>
578
-
</boundary>
579
-
580
-
<boundary>
581
-
<level>5</level>
582
-
<clause>1</clause>
583
-
<where>1</where>
584
-
<ptype>2</ptype>
585
-
<prefix>'+(SELECT '[RANDSTR]' WHERE [RANDNUM]=[RANDNUM]</prefix>
586
-
<suffix>)+'</suffix>
587
-
</boundary>
588
-
<!-- End of INSERT/UPDATE generic boundaries -->
589
-
590
589
<!-- AGAINST boolean full-text search boundaries (http://dev.mysql.com/doc/refman/5.5/en/fulltext-boolean.html) -->
0 commit comments