CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

During a web application assessment, a tester submits a product ID value of 5' UNION SELECT null,null,null-- - and observes the page display three columns of data that match the number of columns in the original query. Which type of SQL injection technique is the tester using?

  1. AUnion-based SQL injection
  2. BBoolean-based blind SQL injection
  3. CStored cross-site scripting
  4. DTime-based blind SQL injection
Show answer & explanation

Correct answer: A. Union-based SQL injection

Union-based SQL injection appends a UNION SELECT statement to combine the results of an injected query with the original query, requiring the attacker to match the column count and often use NULL placeholders to discover it, exactly as described.

Why the other options are wrong

  • B. Boolean-based blind relies on true/false page behavior differences, not visible UNION output.
  • C. Stored XSS involves injecting script code, not SQL syntax.
  • D. Time-based blind relies on database response delays, not returned columns.

Union-Based SQL Injection

An injection technique that appends a UNION SELECT statement to an existing query so attacker-chosen data is returned in the application's output.

  • Requires matching the number of columns in the original query
  • NULL is often used as a placeholder for unknown data types
  • Effective when application output is directly visible to the tester

Memory trick: UNION shows you the data, Boolean whispers true/false, Time makes you wait.

More Attacks and Exploits questions