diff --git a/lib/controller/checks.py b/lib/controller/checks.py index 04183db1d..ba298e3cd 100644 --- a/lib/controller/checks.py +++ b/lib/controller/checks.py @@ -125,7 +125,7 @@ def heuristicCheckSqlInjection(place, parameter, value): if conf.postfix: postfix = conf.postfix - payload = "%s%s%s" % (prefix, randomStr(length=10, alphabet=['"', '\'', ')', '(']), postfix) + payload = "%s%s%s%s" % (value, prefix, randomStr(length=10, alphabet=['"', '\'', ')', '(']), postfix) payload = agent.payload(place, parameter, value, payload) Request.queryPage(payload, place, raise404=False) result = wasLastRequestError()