Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 8484931

Browse files
committed
improvement of heuristic check (now original value is included too)
1 parent 06a872f commit 8484931

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

lib/controller/checks.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -125,7 +125,7 @@ def heuristicCheckSqlInjection(place, parameter, value):
125125
if conf.postfix:
126126
postfix = conf.postfix
127127

128-
payload = "%s%s%s" % (prefix, randomStr(length=10, alphabet=['"', '\'', ')', '(']), postfix)
128+
payload = "%s%s%s%s" % (value, prefix, randomStr(length=10, alphabet=['"', '\'', ')', '(']), postfix)
129129
payload = agent.payload(place, parameter, value, payload)
130130
Request.queryPage(payload, place, raise404=False)
131131
result = wasLastRequestError()

0 commit comments

Comments
 (0)