This commit is contained in:
Bernardo Damele 2011-02-06 22:55:26 +00:00
parent db77f8b055
commit 9eac2339ca

View File

@ -48,8 +48,7 @@ def __oneShotErrorUse(expression, field):
# Forge the error-based SQL injection request
vector = agent.cleanupPayload(kb.injection.data[PAYLOAD.TECHNIQUE.ERROR].vector)
query = unescaper.unescape(vector)
query = agent.prefixQuery(query)
query = agent.prefixQuery(vector)
query = agent.suffixQuery(query)
injExpression = expression.replace(field, nulledCastedField, 1)
injExpression = unescaper.unescape(injExpression)
@ -109,6 +108,7 @@ def __errorFields(expression, expressionFields, expressionFieldsList, expected=N
if output:
output = output.replace(kb.misc.space, " ")
if output is not None:
outputs.append(output)
return outputs