INNER CODE UNIT · Java
query
ron190/jsql-injection · model/src/main/java/com/jsql/model/InjectionModel.java:453
query = paramLeadFixed; // Just pass parameters without any transformation
} else if (
// If method is selected by user and URL does not contain injection point
// but parameters contain an injection point
// then replace injection point by SQL expression in this parameter
paramLeadFixed.contains(InjectionModel.STAR)
) {
query = this.initStarInjection(paramLeadFixed, isUsingIndex, sqlTrail);
} else {
query = this.initRawInjection(paramLeadFixed, isUsingIndex, sqlTrail);
}
query = this.cleanQuery(methodInjection, query); // Remove comments except empty /**/
// Add empty comments with space=>/**/
if (this.mediatorUtils.connectionUtil().getMethodInjection() == methodInjection) {
query = this.mediatorUtils.tamperingUtil().tamper(query);
} else { // remove tags added on non injection point like headers 'Accept: */*'
String regexToRemoveTamperTags = String.format("(?i)%s|%s", TamperingUtil.TAG_OPENED, TamperingUtil.TAG_CLOSED);
query = query.replaceAll(regexToRemoveTamperTags, StringUtils.EMPTY);