Skip to content

Conversation

kingthorin
Copy link
Member

@kingthorin kingthorin commented Jul 4, 2025

Overview

The SQL Injection MsSQL scan rule has been renamed to indicate that it currently only does time based tests (Issue 7341). (The help already indicates that it is time based).

Related Issues

@psiinon
Copy link
Member

psiinon commented Jul 4, 2025

Logo
Checkmarx One – Scan Summary & Detailsb3124253-827c-465d-aa2c-89760a04d0ae

New Issues (2)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
LOW Log_Forging /addOns/exim/src/main/java/org/zaproxy/addon/exim/har/HarUtils.java: 148
detailsMethod at line 148 of /addOns/exim/src/main/java/org/zaproxy/addon/exim/har/HarUtils.java gets user input from element getHeaders. This element’...
ID: H8Mkbf5C3FxJfvGer8egrXfEHEM%3D
Attack Vector
LOW Log_Forging /addOns/exim/src/main/java/org/zaproxy/addon/exim/har/HarUtils.java: 148
detailsMethod at line 148 of /addOns/exim/src/main/java/org/zaproxy/addon/exim/har/HarUtils.java gets user input from element getHeaders. This element’...
ID: xGNeFMn6wYcB801pmPCbdXYgerI%3D
Attack Vector

@kingthorin kingthorin changed the title ascanrules: SQLi MsSQL rename scan rule (all timing based) ascanrules: SQLi MsSQL rename scan rule (all time based) Jul 15, 2025
@kingthorin kingthorin force-pushed the sqli-mssql-split branch 2 times, most recently from 062db50 to a9da643 Compare July 15, 2025 14:06
@thc202
Copy link
Member

thc202 commented Jul 15, 2025

Thank you!

@psiinon psiinon merged commit 356cd51 into zaproxy:main Jul 15, 2025
8 of 9 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Jul 15, 2025
@kingthorin kingthorin deleted the sqli-mssql-split branch July 25, 2025 14:13
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants