Portswigger

1.Union sql injection(Oracle)

post-thumbnail

2.Union sql injection(non-Oracle)

post-thumbnail