From bec4dedbc92fb7fda9d2611646b54ded6ec38e16 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miroslav=20=C5=A0tampar?= Date: Tue, 18 Aug 2026 11:45:44 +0200 Subject: [PATCH] Enabling PostgreSQL file write over a gadget when stacked queries are unavailable --- lib/core/settings.py | 2 +- plugins/generic/filesystem.py | 7 +++++++ 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/lib/core/settings.py b/lib/core/settings.py index e32ce3f8c..15d8df1c9 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -20,7 +20,7 @@ from lib.core.enums import OS from thirdparty import six # sqlmap version (...) -VERSION = "1.10.8.48" +VERSION = "1.10.8.49" TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE) diff --git a/plugins/generic/filesystem.py b/plugins/generic/filesystem.py index 421abc4c2..3898895ab 100644 --- a/plugins/generic/filesystem.py +++ b/plugins/generic/filesystem.py @@ -315,6 +315,13 @@ class Filesystem(object): debugMsg += "stacked query technique" logger.debug(debugMsg) + written = self.stackedWriteFile(localFile, remoteFile, fileType, forceCheck) + self.cleanup(onlyFileTbl=True) + elif Backend.isDbms(DBMS.PGSQL) and inject.getGadget(): + debugMsg = "going to upload the file '%s' with " % fileType + debugMsg += "large object technique through a gadget" + logger.debug(debugMsg) + written = self.stackedWriteFile(localFile, remoteFile, fileType, forceCheck) self.cleanup(onlyFileTbl=True) elif isTechniqueAvailable(PAYLOAD.TECHNIQUE.UNION) and Backend.isDbms(DBMS.MYSQL):