mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2026-08-04 06:50:14 +00:00
Patch related to the #3282
This commit is contained in:
parent
e005ba3f77
commit
5efe3228f8
3 changed files with 6 additions and 3 deletions
|
|
@ -246,6 +246,9 @@ class Agent(object):
|
|||
else:
|
||||
query = kb.injection.prefix or prefix or ""
|
||||
|
||||
if "SELECT '[RANDSTR]'" in query: # escaping of pre-WHERE prefixes
|
||||
query = query.replace("'[RANDSTR]'", unescaper.escape(randomStr(), quote=False))
|
||||
|
||||
if not (expression and expression[0] == ';') and not (query and query[-1] in ('(', ')') and expression and expression[0] in ('(', ')')) and not (query and query[-1] == '('):
|
||||
query += " "
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue