diff --git a/lib/request/templates.py b/lib/request/templates.py index 508488af7..5b9d2054b 100644 --- a/lib/request/templates.py +++ b/lib/request/templates.py @@ -13,7 +13,7 @@ from lib.core.data import kb from lib.request.connect import Connect as Request def getPageTemplate(payload, place): - retVal = kb.originalPage, kb.errorIsNone + retVal = (kb.originalPage, kb.errorIsNone) if payload and place: if (payload, place) not in kb.pageTemplates: @@ -24,4 +24,4 @@ def getPageTemplate(payload, place): return retVal -lib.core.common.getPageTemplate = getPageTemplate \ No newline at end of file +lib.core.common.getPageTemplate = getPageTemplate diff --git a/lib/takeover/xp_cmdshell.py b/lib/takeover/xp_cmdshell.py index d69323869..fc31964f5 100644 --- a/lib/takeover/xp_cmdshell.py +++ b/lib/takeover/xp_cmdshell.py @@ -41,7 +41,7 @@ class xp_cmdshell: self.__randStr = randomStr(lowercase=True) - cmd += "declare @%s nvarchar(999); " % self.__randStr + cmd += "DECLARE @%s nvarchar(999); " % self.__randStr cmd += "set @%s='" % self.__randStr cmd += "CREATE PROCEDURE xp_cmdshell(@cmd varchar(255)) AS DECLARE @ID int " cmd += "EXEC sp_OACreate ''WScript.Shell'', @ID OUT " diff --git a/xml/payloads.xml b/xml/payloads.xml index 5ed9e6262..c1a6deb73 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -481,6 +481,9 @@ Formats: AND [RANDNUM]=[RANDNUM1] +
+ MySQL +