From 6ec6e8693782613dda06879ddac3975ded2d77fb Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Mon, 16 Sep 2019 10:18:51 +0200 Subject: [PATCH] Update regarding #3928 --- data/txt/common-files.txt | 11 +++++++++++ lib/core/settings.py | 2 +- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/data/txt/common-files.txt b/data/txt/common-files.txt index a065db715..05e6ce265 100644 --- a/data/txt/common-files.txt +++ b/data/txt/common-files.txt @@ -192,6 +192,17 @@ /var/log/mysqld.log /var/www/index.php +# Reference: https://github.com/sqlmapproject/sqlmap/blob/master/lib/core/settings.py#L809-L810 + +/var/www/index.php +/usr/local/apache/index.php +/usr/local/apache2/index.php +/usr/local/www/apache22/index.php +/usr/local/www/apache24/index.php +/usr/local/httpd/index.php +/var/www/nginx-default/index.php +/srv/www/index.php + # Reference: https://www.gracefulsecurity.com/path-traversal-cheat-sheet-linux /etc/passwd diff --git a/lib/core/settings.py b/lib/core/settings.py index 0984aacf7..d8afe5599 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -18,7 +18,7 @@ from lib.core.enums import OS from thirdparty.six import unichr as _unichr # sqlmap version (...) -VERSION = "1.3.9.16" +VERSION = "1.3.9.17" TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)