{keyword}' Union All Select Null,null,null,null,null,null,null,null-- Jynz May 2026
If the original query has 8 columns, the page will likely load normally or show an extra row of empty data.
This specific string is designed to be appended to a vulnerable input field (the {KEYWORD} in your example) to probe the database structure: : Closes the original string literal in the SQL query. If the original query has 8 columns, the
: This is a SQL comment, which tells the database to ignore the rest of the original, legitimate query that follows. The Goal of the Attack The Goal of the Attack : Appends a
: Appends a new set of results to the original query's output. legitimate query that follows.
The primary objective of using this payload is . For a UNION operation to work, the injected query must have the exact same number of columns as the original query.