sql - Sqlmap inline parameters -


hi ive hear error in cakephp allows sql inyection; https://twitter.com/cakephp/status/328610604778651649

i trying test site using sqlmap, cant find how specify params.

the url testing is;

http://127.0.0.1/categories/index/page:1/sort:id/direction:asc 

and parameters want sqlmap inyect in url (page:,sort:,direction:)

i have try run;

python sqlmap.py -u "http://127.0.0.1/categories/index/page:1/sort:id/direction:asc" 

but nothing... clue? thanks!

in cakephp there passed arguments, named parameters, , querystring parameters.

passed arguments .../index/arg accessed $this->request->pass[0], '0' array index. named parameters .../index/key:value , accessed $this->request->named['key']. querystring parameters ̀.../index?key=valueand accessed with$this->request->query['key']`.

your url uses named parameters should (without question mark):

http://127.0.0.1/categories/index/page:1/sort:id/direction:asc 

edit:

since cakephp uses mod_rewrite, have specify parameters explained in sqlmap wiki.


Comments

Popular posts from this blog

linux - Does gcc have any options to add version info in ELF binary file? -

android - send complex objects as post php java -

charts - What graph/dashboard product is facebook using in Dashboard: PUE & WUE -