mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-02-03 13:14:13 +03:00
fix for user-agent injections
This commit is contained in:
parent
818c9787b2
commit
c1145c244e
|
@ -104,8 +104,10 @@ class Agent:
|
|||
child.text = self.addPayloadDelimiters(newValue)
|
||||
|
||||
retValue = ET.tostring(root)
|
||||
elif place in (PLACE.UA, PLACE.URI):
|
||||
elif place == PLACE.URI:
|
||||
retValue = paramString.replace("%s*" % origValue, self.addPayloadDelimiters(newValue))
|
||||
elif place == PLACE.UA:
|
||||
retValue = paramString.replace(origValue, self.addPayloadDelimiters(newValue))
|
||||
else:
|
||||
retValue = paramString.replace("%s=%s" % (parameter, origValue),
|
||||
"%s=%s" % (parameter, self.addPayloadDelimiters(newValue)))
|
||||
|
|
Loading…
Reference in New Issue
Block a user