mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-06 20:51:31 +00:00
added conf.unescape global variable to control whether or not the injected statements should be unescaped
This commit is contained in:
@@ -1548,8 +1548,10 @@ def getSQLSnippet(dbms, sfile, **variables):
|
|||||||
Returns content of SQL snippet located inside 'procs/' directory
|
Returns content of SQL snippet located inside 'procs/' directory
|
||||||
"""
|
"""
|
||||||
|
|
||||||
if os.path.exists(sfile):
|
if sfile.endswith('.sql') and os.path.exists(sfile):
|
||||||
filename = sfile
|
filename = sfile
|
||||||
|
elif not sfile.endswith('.sql') and os.path.exists("%s.sql" % sfile):
|
||||||
|
filename = "%s.sql" % sfile
|
||||||
else:
|
else:
|
||||||
filename = os.path.join(paths.SQLMAP_PROCS_PATH, DBMS_DIRECTORY_DICT[dbms], sfile if sfile.endswith('.sql') else "%s.sql" % sfile)
|
filename = os.path.join(paths.SQLMAP_PROCS_PATH, DBMS_DIRECTORY_DICT[dbms], sfile if sfile.endswith('.sql') else "%s.sql" % sfile)
|
||||||
checkFile(filename)
|
checkFile(filename)
|
||||||
|
|||||||
@@ -1402,6 +1402,7 @@ def __setConfAttributes():
|
|||||||
conf.tests = []
|
conf.tests = []
|
||||||
conf.trafficFP = None
|
conf.trafficFP = None
|
||||||
conf.wFileType = None
|
conf.wFileType = None
|
||||||
|
conf.unescape = True
|
||||||
|
|
||||||
def __setKnowledgeBaseAttributes(flushAll=True):
|
def __setKnowledgeBaseAttributes(flushAll=True):
|
||||||
"""
|
"""
|
||||||
|
|||||||
Reference in New Issue
Block a user