From 81011be0d7ef25c2a4dd88cec97319780c42ab21 Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Mon, 24 Jan 2011 14:52:50 +0000 Subject: [PATCH] minor update of parseTargetUrl method --- lib/core/common.py | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/lib/core/common.py b/lib/core/common.py index c72b26b6c..09c4704e0 100644 --- a/lib/core/common.py +++ b/lib/core/common.py @@ -684,9 +684,13 @@ def parseTargetUrl(): __urlSplit = urlparse.urlsplit(conf.url) __hostnamePort = __urlSplit[1].split(":") - conf.scheme = __urlSplit[0] - conf.path = __urlSplit[2] - conf.hostname = __hostnamePort[0] + conf.scheme = __urlSplit[0].strip() + conf.path = __urlSplit[2].strip() + conf.hostname = __hostnamePort[0].strip() + + if re.search(r'\s', conf.hostname): + errMsg = "invalid target url" + raise sqlmapSyntaxException, errMsg if len(__hostnamePort) == 2: try: