SQL injection UNION attack, determining the number of columns returned by the query | Practitioner
The most glaring functionality present is filtering products by category, as shown here:

As reflected in the lab’s name, the first step of a UNION-based SQLi is to determine the number of columns. We can either union order by index or select by NULL, whatever floats your boat.
Note that NULL works because it’s convertible to every common data type, thus makes our payload more likely to succeed.
Assuming there is no WAF nor client-side filters in place (which there aren’t), we can apply our elementary payload:
` UNION SELECT NULL--

Though the request is invalid, the server does indeed return a 500, which means it’s actually processing the query rather than chopping our payload off. Since this basically confirms the lack of filters, we can keep adding , NULL-- until the number of columns matches:
The server now returns a 500 after 3 NULLs, corresponding to three columns in the database. Neat!