Multi step Stored XSS and Stored SQLI

Karthik | Last updated: Apr 28, 2020 12:21PM UTC

For my research on blackbox scanners efficiency testing, I configured scans using burpsuite professional version for known vulnerable web application Wackopicko and my own custom test bed with one stored XSS and SQLI vulnerability and I found burp is unable to found the vulnerability even when it is listening as proxy for unsanitized input and manually exploiting this vulnerabilities. Can I know is there any way to detect the Multi step stored XSS and Stored SQLI using burp.

Liam, PortSwigger Agent | Last updated: Apr 28, 2020 01:50PM UTC

Thanks for this report. Would it be possible to send us requests and responses detailing how you proved the issues manually?

