The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Check the solution for SQL injection

Jineesh | Last updated: Jun 06, 2021 07:33PM UTC

Hi Support, We are getting an SQL injection issue in the scan result for the below URL GET /SAML/SingleSignOn?ReturnUrl=%2f&(select%20load_file('%5c%5c%5c%5cksg8fmv7bu5rjhreg45vab9cg3mwaqyh05uskg9.burpcollaborator.net%5c%5cvxz'))=1 HTTP/2 But when we check the URL in the browser we are getting 500 server error. Because this is blocked by our FortiWeb web applciation firewall. Bu why this is listed in the scan result Thanks, Jineesh

Jineesh | Last updated: Jun 07, 2021 06:22AM UTC

Hi Guyz, Any update on this. I just want to know why the URL listed as an SQL injection even if the request is blocked by WAF Thanks, Jineesh

Uthman, PortSwigger Agent | Last updated: Jun 07, 2021 11:07AM UTC