{keyword}' Union All — Select Null,null,null,null,null,null,null,null From Msysaccessobjects-- Udhz
Sources:[1] microsoft.com[2] portswigger.net[3] geeksforgeeks.org[4] sqlinjection.net[5] owasp.org[6] owasp.org
Only allow the types of characters you expect (e.g., numbers for an ID field). Sources:[1] microsoft
Comments out the rest of the original query so it doesn't cause a syntax error [1, 5]. How to Prevent It: 5]. How to Prevent It: