mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-01-24 08:14:24 +03:00
Proper fix for r3307 (file-write on MySQL via UNION query tech)
This commit is contained in:
parent
417b311475
commit
2ea828e416
|
@ -434,11 +434,14 @@ class Agent:
|
|||
@rtype: C{str}
|
||||
"""
|
||||
|
||||
if not unpack:
|
||||
return query
|
||||
else:
|
||||
concatenatedQuery = query
|
||||
if unpack:
|
||||
concatenatedQuery = ""
|
||||
query = query.replace(", ", ",")
|
||||
fieldsSelectFrom, fieldsSelect, fieldsNoSelect, fieldsSelectTop, fieldsSelectCase, _, fieldsToCastStr, fieldsExists = self.getFields(query)
|
||||
castedFields = self.nullCastConcatFields(fieldsToCastStr)
|
||||
concatenatedQuery = query.replace(fieldsToCastStr, castedFields, 1)
|
||||
else:
|
||||
return query
|
||||
|
||||
if Backend.getIdentifiedDbms() == DBMS.MYSQL:
|
||||
if fieldsExists:
|
||||
|
|
Loading…
Reference in New Issue
Block a user