diff --git a/tamper/unmagicquotes.py b/tamper/unmagicquotes.py index d56136f7f..8f92f5d3a 100644 --- a/tamper/unmagicquotes.py +++ b/tamper/unmagicquotes.py @@ -26,7 +26,9 @@ def tamper(payload, **kwargs): * http://shiflett.org/blog/2006/jan/addslashes-versus-mysql-real-escape-string >>> tamper("1' AND 1=1") - '1%bf%27 AND 1=1-- ' + '1%bf%27 AND 1=1' + >>> tamper("1' AND '1'='1") + '1%bf%27-- ' """ retVal = payload