SQL injection UNION attack, finding a column containing text | Practitioner
The problem statement hints at the filter functionality has an SQLi vulnerability, and similar to last lab we have to find how many columns are there first, then find out which column holds string data.
Finding the number of columns is trivial, either use order by index or union select with NULL:

We now know that there are 3 columns in the table. However our goal is to make the backend returns a certain canary, but we don’t know which column is compatible with string data yet. This is quite simple, all we have to do is place some string value into each column in turn:
' UNION SELECT 'a',NULL,NULL--
' UNION SELECT NULL,'a',NULL--
' UNION SELECT NULL,NULL,'a'--
Now we know the second column can hold strings, now it’s cake walk to get the backend to return our canary:
