mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-06 12:41:30 +00:00
Fixed character escaping in SQL shell/query functionalities.
This commit is contained in:
@@ -30,6 +30,7 @@ from lib.core.agent import agent
|
||||
from lib.core.common import getRange
|
||||
from lib.core.common import parsePasswordHash
|
||||
from lib.core.common import readInput
|
||||
from lib.core.convert import urlencode
|
||||
from lib.core.data import conf
|
||||
from lib.core.data import kb
|
||||
from lib.core.data import logger
|
||||
@@ -1100,6 +1101,8 @@ class Enumeration:
|
||||
selectQuery = True
|
||||
sqlType = None
|
||||
|
||||
query = urlencode(query, convall=True)
|
||||
|
||||
for sqlTitle, sqlStatements in SQL_STATEMENTS.items():
|
||||
for sqlStatement in sqlStatements:
|
||||
if query.lower().startswith(sqlStatement):
|
||||
|
||||
Reference in New Issue
Block a user