Is there any way to execute multiple sql commands inside dbms_xmlquery.getxml or DBMS_XMLGEN.getXML(..) or other PL/SQL xml functions?

Viewed 159

I found an article with example of executing dynamic PL\SQL code inside of dbms_xmlquery.getxml(..) function. This article is https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/OracleSQL%20Injection.md#oracle-sql-list-table . The example like this:

SELECT TO_CHAR(dbms_xmlquery.getxml('declare PRAGMA AUTONOMOUS_TRANSACTION; 
begin execute immediate ... end;')) results FROM dual;

But all my attempts to execute something except of valid "SELECT" statement are falling into error inside xlm response:

<ERROR>oracle.xml.sql.OracleXMLSQLException: Invalid query </ERROR>.

Even query like this

SELECT TO_CHAR(dbms_xmlquery.getxml('begin execute immediate '' begin select 1 from dual; end;'' end;')) results FROM dual;

But query

SELECT TO_CHAR(dbms_xmlquery.getxml('select 1 from dual')) results FROM dual;

works fine.

0 Answers
Related