SQL Injection - Lab #3 SQLi UNION attack determining the number of columns returned by the query

Опубликовано: 05 Июль 2026
на канале: Rana Khalil
129,255
887

In this video, we cover Lab #3 in the SQL injection track of the Web Security Academy. This lab contains a SQL injection vulnerability in the product filter category field. This vulnerability can be exploited using a UNION attack to retrieve data from other tables. To solve the lab, we perform a SQL injection attack that determines the number of columns that are being returned by the query.This is the first step of a SQL injection UNION attack. We'll use this technique in subsequent labs to construct the full attack.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ Links ▬▬▬▬▬▬▬▬▬▬
Detailed video:    • SQL Injection - Lab #3 SQLi UNION attack d...  
SQL injection Lab #2 video (previous video):    • SQL Injection - Lab #2 SQL injection vulne...  
SQL Injection | Complete Guide (theory video):    • SQL Injection | Complete Guide  
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy: https://portswigger.net/web-security​​
Rana's Twitter account:   / rana__khalil