diff --git a/tamper/doubleencode.py b/tamper/doubleencode.py index 311eb10e9..04597e6e8 100644 --- a/tamper/doubleencode.py +++ b/tamper/doubleencode.py @@ -1,11 +1,15 @@ import re from lib.core.convert import urlencode +from lib.core.exception import sqlmapUnsupportedFeatureException """ Tampering value -> urlencode(value) """ def tamper(place, value): if value: - value = urlencode(value) + if place != "URI": + value = urlencode(value) + else: + raise sqlmapUnsupportedFeatureException, "can't use tampering module 'doubleencode.py' with 'URI' type injections" return value