From be6767b3b0585bc0a8000c4804763b6472a7d0ce Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Mon, 10 Feb 2014 09:59:57 +0000 Subject: [PATCH] minor fix for command execution via web shell --- lib/takeover/web.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/lib/takeover/web.py b/lib/takeover/web.py index 3aa83e4f1..e333fe062 100644 --- a/lib/takeover/web.py +++ b/lib/takeover/web.py @@ -235,6 +235,7 @@ class Web: if "sqlmap file uploader" in uplPage: uploaded = True + break # Fall-back to UNION queries file upload technique if not uploaded: @@ -273,6 +274,8 @@ class Web: if "sqlmap file uploader" in uplPage: uploaded = True + break + if not uploaded: self.webBaseUrl = "%s://%s:%d/" % (conf.scheme, conf.hostname, conf.port) self.webStagerUrl = os.path.join(self.webBaseUrl, stagerName)