minor update (tainted values are not checked any more in multipleTargets mode)

This commit is contained in:
Miroslav Stampar 2012-05-25 09:52:17 +00:00
parent dc20bff1d0
commit db526bdbc0

View File

@ -539,6 +539,7 @@ def paramToDict(place, parameters=None):
if condition:
testableParameters[parameter] = "=".join(elem[1:])
if not conf.multipleTargets:
if testableParameters[parameter].strip(DUMMY_SQL_INJECTION_CHARS) != testableParameters[parameter]\
or re.search(r'\A9{3,}', testableParameters[parameter]) or re.search(DUMMY_USER_INJECTION, testableParameters[parameter]):
warnMsg = "it appears that you have provided tainted parameter values "