Fixes #6132
Some checks are pending
/ build (macos-latest, 3.8) (push) Waiting to run
/ build (ubuntu-latest, pypy-2.7) (push) Waiting to run
/ build (windows-latest, 3.14) (push) Waiting to run

This commit is contained in:
Miroslav Štampar 2026-09-28 09:01:30 +02:00
parent a6e832bb8e
commit 4d518ff813
2 changed files with 10 additions and 3 deletions

View file

@ -15,6 +15,7 @@ import time
from extra.beep.beep import beep
from lib.core.agent import agent
from lib.core.common import Backend
from lib.core.common import arrayizeValue
from lib.core.common import extractRegexResult
from lib.core.common import extractStructuralTokens
from lib.core.common import extractTextTagContent
@ -183,7 +184,11 @@ def checkSqlInjection(place, parameter, value):
if kb.reduceTests is None and not conf.testFilter and (intersect(Backend.getErrorParsedDBMSes(), SUPPORTED_DBMS, True) or kb.heuristicDbms or injection.dbms):
msg = "it looks like the back-end DBMS is '%s'. " % (Format.getErrorParsedDBMSes() or kb.heuristicDbms or joinValue(injection.dbms, '/'))
msg += "Do you want to skip test payloads specific for other DBMSes? [Y/n]"
kb.reduceTests = (Backend.getErrorParsedDBMSes() or [kb.heuristicDbms]) if readInput(msg, default='Y', boolean=True) else []
# mirror msg's fallback chain (error-parsed -> heuristic -> injection.dbms) - falling
# back only through the first two (as before) left kb.reduceTests as [None] whenever
# injection.dbms alone satisfied the 'if' above, silently skipping every DBMS-specific
# test payload for the rest of the scan
kb.reduceTests = (Backend.getErrorParsedDBMSes() or ([kb.heuristicDbms] if kb.heuristicDbms else arrayizeValue(injection.dbms))) if readInput(msg, default='Y', boolean=True) else []
# If the DBMS has been fingerprinted (via DBMS-specific error
# message, via simple heuristic check or via DBMS-specific
@ -925,7 +930,9 @@ def heuristicCheckDbms(injection):
may be
"""
retVal = False
# None (not False) on failure - every caller gates re-running this on 'kb.heuristicDbms is
# None', and a stale False from an earlier parameter's failed check would wrongly block that
retVal = None
if conf.skipHeuristics:
return retVal

View file

@ -20,7 +20,7 @@ from lib.core.enums import OS
from thirdparty import six
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
VERSION = "1.10.9.30"
VERSION = "1.10.9.31"
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)