SQL injection Cheat Sheet - Acunetix

This type of SQL injection is possible only for some databases, for example, Microsoft SQL Server and Oracle The attacker includes a special database command in the payload – this command causes a request to an external resource (controlled by the attacker) The attacker monitors for attempts to contact the external resource, for example, ................