INNER CODE UNIT · Java
initRawInjection
ron190/jsql-injection · model/src/main/java/com/jsql/model/InjectionModel.java:475
private String initRawInjection(String paramLead, boolean isUsingIndex, String sqlTrail) {
String query;
// Method is selected by user and there's no injection point
if (!isUsingIndex) {
// Several SQL expressions does not use indexes in SELECT,
// like Boolean, Error, Shell and search for character insertion,
// in that case concat SQL expression to the end of param.
query = paramLead + sqlTrail;
} else {
// Concat indexes found for Union strategy to params
// and use visible Index for injection
query = paramLead + this.getMediatorStrategy().getSpecificUnion().getIndexesInUrl().replaceAll(
String.format(EngineYaml.FORMAT_INDEX, this.mediatorStrategy.getSpecificUnion().getVisibleIndex()),
// Oracle column often contains $, which is reserved for regex.
// => need to be escape with quoteReplacement()
Matcher.quoteReplacement(sqlTrail)
);
}