Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 797bc7b

Browse files
committed
Fixes #3762
1 parent 8220b62 commit 797bc7b

2 files changed

Lines changed: 4 additions & 2 deletions

File tree

lib/core/settings.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
from thirdparty.six import unichr as _unichr
1919

2020
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
21-
VERSION = "1.3.6.44"
21+
VERSION = "1.3.6.45"
2222
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
2323
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
2424
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)

tamper/randomcase.py

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,8 @@ def tamper(payload, **kwargs):
4141
'f()'
4242
>>> tamper('function()')
4343
'FuNcTiOn()'
44+
>>> tamper('SELECT id FROM `user`')
45+
'SeLeCt id FrOm `user`'
4446
"""
4547

4648
retVal = payload
@@ -49,7 +51,7 @@ def tamper(payload, **kwargs):
4951
for match in re.finditer(r"\b[A-Za-z_]{2,}\b", retVal):
5052
word = match.group()
5153

52-
if word.upper() in kb.keywords or ("%s(" % word) in payload:
54+
if (word.upper() in kb.keywords and re.search(r"(?i)[`\"\[]%s[`\"\]]" % word, retVal) is None) or ("%s(" % word) in payload:
5355
while True:
5456
_ = ""
5557

0 commit comments

Comments
 (0)