The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Mitigate the Risk of SQL Lite injection via CSS

Stephen | Last updated: Nov 07, 2023 06:18AM UTC

Hi, Your tools have reportedly found an "issue" with our site, but I dont know how to fix. The team validated the SQL Injection vulnerability identified by OWASP ZAP using Burpsuite and the query time is controllable using parameter value [case randomblob(100000) when not null then 1 else 1 end ], which caused the requests to have different response times. I don't understand how to address this ? Any pointers ? The url hit is a CSS file with a query in the parameter string.. We dont use SQLLite - we are LAMP mostly... Any advise would be appreciated ? Steve

Hannah, PortSwigger Agent | Last updated: Nov 07, 2023 10:35AM UTC