diff --git a/lib/controller/checks.py b/lib/controller/checks.py index a6e33fbc3..ffd56f9e8 100644 --- a/lib/controller/checks.py +++ b/lib/controller/checks.py @@ -341,10 +341,14 @@ def checkSqlInjection(place, parameter, value): trueResult = Request.queryPage(reqPayload, place, timeBasedCompare=True) if trueResult: - infoMsg = "%s parameter '%s' is '%s' injectable " % (place, parameter, title) - logger.info(infoMsg) + # Confirm test's results + trueResult = Request.queryPage(reqPayload, place, timeBasedCompare=True) - injectable = True + if trueResult: + infoMsg = "%s parameter '%s' is '%s' injectable " % (place, parameter, title) + logger.info(infoMsg) + + injectable = True # Restore value of socket timeout socket.setdefaulttimeout(popValue())