Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit ab32ad4

Browse files
committed
Fixes #3471
1 parent 0a42d91 commit ab32ad4

4 files changed

Lines changed: 26 additions & 9 deletions

File tree

lib/core/common.py

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2994,16 +2994,21 @@ def parseSqliteTableSchema(value):
29942994
Parses table column names and types from specified SQLite table schema
29952995
"""
29962996

2997+
retVal = False
2998+
29972999
if value:
29983000
table = {}
29993001
columns = {}
30003002

30013003
for match in re.finditer(r"(\w+)[\"'`]?\s+(INT|INTEGER|TINYINT|SMALLINT|MEDIUMINT|BIGINT|UNSIGNED BIG INT|INT2|INT8|INTEGER|CHARACTER|VARCHAR|VARYING CHARACTER|NCHAR|NATIVE CHARACTER|NVARCHAR|TEXT|CLOB|LONGTEXT|BLOB|NONE|REAL|DOUBLE|DOUBLE PRECISION|FLOAT|REAL|NUMERIC|DECIMAL|BOOLEAN|DATE|DATETIME|NUMERIC)\b", value, re.I):
3004+
retVal = True
30023005
columns[match.group(1)] = match.group(2)
30033006

3004-
table[conf.tbl] = columns
3007+
table[safeSQLIdentificatorNaming(conf.tbl, True)] = columns
30053008
kb.data.cachedColumns[conf.db] = table
30063009

3010+
return retVal
3011+
30073012
def getTechniqueData(technique=None):
30083013
"""
30093014
Returns injection data for technique specified

lib/core/settings.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
from lib.core.enums import OS
2020

2121
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
22-
VERSION = "1.3.2.8"
22+
VERSION = "1.3.2.9"
2323
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
2424
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
2525
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)

plugins/generic/databases.py

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -622,7 +622,13 @@ def getColumns(self, onlyColNames=False, colTuple=None, bruteForce=None, dumpMod
622622
index += 1
623623

624624
if Backend.isDbms(DBMS.SQLITE):
625-
parseSqliteTableSchema(unArrayizeValue(values))
625+
if dumpMode and colList:
626+
if conf.db not in kb.data.cachedColumns:
627+
kb.data.cachedColumns[conf.db] = {}
628+
kb.data.cachedColumns[conf.db][safeSQLIdentificatorNaming(conf.tbl, True)] = dict((_,None) for _ in colList)
629+
else:
630+
parseSqliteTableSchema(unArrayizeValue(values))
631+
626632
elif not isNoneValue(values):
627633
table = {}
628634
columns = {}
@@ -718,9 +724,15 @@ def getColumns(self, onlyColNames=False, colTuple=None, bruteForce=None, dumpMod
718724
query += condQuery
719725

720726
elif Backend.isDbms(DBMS.SQLITE):
721-
query = rootQuery.blind.query % unsafeSQLIdentificatorNaming(tbl)
722-
value = unArrayizeValue(inject.getValue(query, union=False, error=False))
723-
parseSqliteTableSchema(value)
727+
if dumpMode and colList:
728+
if conf.db not in kb.data.cachedColumns:
729+
kb.data.cachedColumns[conf.db] = {}
730+
kb.data.cachedColumns[conf.db][safeSQLIdentificatorNaming(conf.tbl, True)] = dict((_,None) for _ in colList)
731+
else:
732+
query = rootQuery.blind.query % unsafeSQLIdentificatorNaming(tbl)
733+
value = unArrayizeValue(inject.getValue(query, union=False, error=False))
734+
parseSqliteTableSchema(unArrayizeValue(value))
735+
724736
return kb.data.cachedColumns
725737

726738
table = {}

txt/checksum.md5

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ c1da277517c7ec4c23e953a51b51e203 lib/controller/handler.py
3030
fb6be55d21a70765e35549af2484f762 lib/controller/__init__.py
3131
ed7874be0d2d3802f3d20184f2b280d5 lib/core/agent.py
3232
a932126e7d80e545c5d44af178d0bc0c lib/core/bigarray.py
33-
e253cc58cb0d2bc01a68cfbe58266435 lib/core/common.py
33+
964885db1ac028fa622ee5ba20f061b1 lib/core/common.py
3434
de8d27ae6241163ff9e97aa9e7c51a18 lib/core/convert.py
3535
abcb1121eb56d3401839d14e8ed06b6e lib/core/data.py
3636
e1f7758f433202c50426efde5eb96768 lib/core/datatype.py
@@ -50,7 +50,7 @@ d5ef43fe3cdd6c2602d7db45651f9ceb lib/core/readlineng.py
5050
7d8a22c582ad201f65b73225e4456170 lib/core/replication.py
5151
3179d34f371e0295dd4604568fb30bcd lib/core/revision.py
5252
d6269c55789f78cf707e09a0f5b45443 lib/core/session.py
53-
ccda855c6b8c67a67867fba4047446d6 lib/core/settings.py
53+
0f7113b9afe5f0b0051a65bbd5d4a713 lib/core/settings.py
5454
4483b4a5b601d8f1c4281071dff21ecc lib/core/shell.py
5555
10fd19b0716ed261e6d04f311f6f527c lib/core/subprocessng.py
5656
43772ea73e9e3d446f782af591cb4eda lib/core/target.py
@@ -215,7 +215,7 @@ ec3f406591fc9472f5750bd40993e72e plugins/dbms/sybase/syntax.py
215215
369476221b3059106410de05766227e0 plugins/dbms/sybase/takeover.py
216216
312020bc31ffb0bc6077f62e6fff6e73 plugins/generic/connector.py
217217
d749b7f7b4bcf1f646290dec739f1e6d plugins/generic/custom.py
218-
791db3be35714c9a2e55a7abe9127da4 plugins/generic/databases.py
218+
69cc329dc01805c1a7d6d65534a3e719 plugins/generic/databases.py
219219
4cf8eb3719c980c54a92f838a999d090 plugins/generic/entries.py
220220
f3624debb8ae6fbcfb5f1b7f1d0743d1 plugins/generic/enumeration.py
221221
cda119b7b0d1afeb60f912009cdb0cf5 plugins/generic/filesystem.py

0 commit comments

Comments
 (0)