SQL injection Cheat Sheet - Acunetix

As a result, if the current user (current database user) has suitable permissions, the entire users table is cleared. This type of SQL injection is possible only for some databases, for example, Microsoft SQL Server and Oracle The attacker includes a special database command in the payload – this command causes a request to an external resource (controlled by the attacker) The attacker ... ................
................