Skip to content

Commit 4d518ff

Browse files
committed
Fixes #6132
1 parent a6e832b commit 4d518ff

2 files changed

Lines changed: 10 additions & 3 deletions

File tree

‎lib/controller/checks.py‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@
1515
from extra.beep.beep import beep
1616
from lib.core.agent import agent
1717
from lib.core.common import Backend
18+
from lib.core.common import arrayizeValue
1819
from lib.core.common import extractRegexResult
1920
from lib.core.common import extractStructuralTokens
2021
from lib.core.common import extractTextTagContent
@@ -183,7 +184,11 @@ def checkSqlInjection(place, parameter, value):
183184
if kb.reduceTests is None and not conf.testFilter and (intersect(Backend.getErrorParsedDBMSes(), SUPPORTED_DBMS, True) or kb.heuristicDbms or injection.dbms):
184185
msg = "it looks like the back-end DBMS is '%s'. " % (Format.getErrorParsedDBMSes() or kb.heuristicDbms or joinValue(injection.dbms, '/'))
185186
msg += "Do you want to skip test payloads specific for other DBMSes? [Y/n]"
186-
kb.reduceTests = (Backend.getErrorParsedDBMSes() or [kb.heuristicDbms]) if readInput(msg, default='Y', boolean=True) else []
187+
# mirror msg's fallback chain (error-parsed -> heuristic -> injection.dbms) - falling
188+
# back only through the first two (as before) left kb.reduceTests as [None] whenever
189+
# injection.dbms alone satisfied the 'if' above, silently skipping every DBMS-specific
190+
# test payload for the rest of the scan
191+
kb.reduceTests = (Backend.getErrorParsedDBMSes() or ([kb.heuristicDbms] if kb.heuristicDbms else arrayizeValue(injection.dbms))) if readInput(msg, default='Y', boolean=True) else []
187192

188193
# If the DBMS has been fingerprinted (via DBMS-specific error
189194
# message, via simple heuristic check or via DBMS-specific
@@ -925,7 +930,9 @@ def heuristicCheckDbms(injection):
925930
may be
926931
"""
927932

928-
retVal = False
933+
# None (not False) on failure - every caller gates re-running this on 'kb.heuristicDbms is
934+
# None', and a stale False from an earlier parameter's failed check would wrongly block that
935+
retVal = None
929936

930937
if conf.skipHeuristics:
931938
return retVal

‎lib/core/settings.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
from thirdparty import six
2121

2222
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
23-
VERSION = "1.10.9.30"
23+
VERSION = "1.10.9.31"
2424
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
2525
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
2626
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)

0 commit comments

Comments
 (0)