Dirty patch for #5488

This commit is contained in:
Miroslav Stampar
2023-08-19 10:02:29 +02:00
parent 3e98fabd23
commit ccc38abff6
2 changed files with 6 additions and 1 deletions

View File

@@ -185,6 +185,11 @@ class Agent(object):
newValue = newValue.replace(BOUNDARY_BACKSLASH_MARKER, '\\')
newValue = self.adjustLateValues(newValue)
# NOTE: https://github.com/sqlmapproject/sqlmap/issues/5488
if kb.customInjectionMark in origValue:
payload = newValue.replace(origValue, "")
newValue = origValue.replace(kb.customInjectionMark, payload)
# TODO: support for POST_HINT
newValue = "%s%s%s" % (BOUNDED_BASE64_MARKER, newValue, BOUNDED_BASE64_MARKER)