From bf5ca4bd9a4b37d85d7f3eb7d1447ac4e45a044f Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Sun, 6 Feb 2011 23:30:43 +0000 Subject: [PATCH] No point in unescaping the expression also in suffixQuery() also 'cause it will exit sqlmap if the parameter value is a string hence injection payload starts with single quote (') --- lib/core/agent.py | 1 - 1 file changed, 1 deletion(-) diff --git a/lib/core/agent.py b/lib/core/agent.py index 48652c36c..ca935849a 100644 --- a/lib/core/agent.py +++ b/lib/core/agent.py @@ -181,7 +181,6 @@ class Agent: return self.payloadDirect(expression) expression = self.cleanupPayload(expression) - expression = unescaper.unescape(expression) if comment is not None: expression += comment