Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

SQLi detection after custom parsing output #3129

Copy link
Copy link
@QFTx

Description

@QFTx
Issue body actions

Hey,
I stumbled upon what I think is a valid SQLi during an engagement.
I identified it manually first, then attempted to use sqlmap which is unable to detect the injection.

I noticed that sql error in response is embedded in a custom url encoded META tag content. The truncated tag looks something like this:
<META name="truncated" content="ORA-01722%3A%20invalid%20number..........">

I can see it throwing multiple error such as: ORA-01722: invalid number
However, it seems to be url encoded and thats why sqlmap can't see it?
Or could it be becuase response need to be manipulated (strip down HTML tags and urldecode).

I have no issues trying things out just want to see if this has been addressed before.

Reactions are currently unavailable

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    Morty Proxy This is a proxified and sanitized view of the page, visit original site.