mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2026-01-10 00:29:02 +00:00
Patch for MsSQL column name injection
This commit is contained in:
@@ -513,8 +513,8 @@ Formats:
|
||||
<clause>8</clause>
|
||||
<where>1</where>
|
||||
<ptype>6</ptype>
|
||||
<prefix>]=[[ORIGINAL]]</prefix>
|
||||
<suffix> AND [[ORIGINAL]]=[[ORIGINAL]</suffix>
|
||||
<prefix>]-(SELECT 0 WHERE [RANDNUM]=[RANDNUM]</prefix>
|
||||
<suffix>)|[[ORIGINAL]</suffix>
|
||||
</boundary>
|
||||
<!-- End of escaped column name boundaries -->
|
||||
|
||||
|
||||
Reference in New Issue
Block a user