mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2026-01-30 10:09:03 +00:00
added protection mechanism against reflected values
This commit is contained in:
@@ -265,3 +265,6 @@ MYSQL_ERROR_CHUNK_LENGTH = 50
|
||||
|
||||
# Do not unescape the injected statement if it contains any of the following SQL words
|
||||
EXCLUDE_UNESCAPE = ("WAITFOR DELAY ", " INTO DUMPFILE ", " INTO OUTFILE ", "CREATE ", "BULK ", "EXEC ", "RECONFIGURE ", "DECLARE ", CHAR_INFERENCE_MARK)
|
||||
|
||||
# Mark used for replacement of reflected values
|
||||
REFLECTED_VALUE_MARKER = '__REFLECTED_VALUE__'
|
||||
|
||||
Reference in New Issue
Block a user