Menu

#1628 SQL injection should be excluded/skipped in Active scan when Technology/Db is unchecked

Duplicate
nobody
None
Medium
Defect
2015-05-08
2015-05-08
Anonymous
No

Originally created by: ath...@gmail.com

When there is a need to scan a static site which you already know it doesn't talk to a DB, the SQL injection step should not occur during active scan.
This could save time.

What steps will reproduce the problem?
1. Start an Active scan and uncheck 'Db'.
2. Start the scan and notice that 'SQL injection' is processed.

What is the expected output? What do you see instead?
'SQL injection' should be excluded or automatically skipped.

What version of the product are you using? On what operating system?
2.4.0 / Win7, 64-bit

Please provide any additional information below.
See attached screenshot.

1 Attachments

Related

Tickets: #1618

Discussion

  • Anonymous

    Anonymous - 2015-05-08

    Originally posted by: psii...@gmail.com

    (No comment was entered for this change.)

    Status: Accepted

     
  • Anonymous

    Anonymous - 2015-05-08

    Originally posted by: THC...@gmail.com

    (No comment was entered for this change.)

    Mergedinto: 1618
    Status: Duplicate

     

Log in to post a comment.

MongoDB Logo MongoDB