mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-07 13:11:29 +00:00
Ugly work-around to avoid unescaping WAITFOR DELAY time between single quotes (unescaped CHAR(..) value does not work).
This commit is contained in:
@@ -69,7 +69,7 @@ def unescape(string, dbms):
|
||||
"Sybase": Sybase.unescape
|
||||
}
|
||||
|
||||
if dbms in unescaper:
|
||||
if dbms in unescaper and "WAITFOR DELAY " not in string:
|
||||
return unescaper[dbms](string)
|
||||
else:
|
||||
return string
|
||||
|
||||
Reference in New Issue
Block a user