epinna / tplmap

Server-Side Template Injection and Code Injection Detection and Exploitation Tool
GNU General Public License v3.0
3.75k stars 670 forks source link

Could it be false positive? #34

Closed 007scorpio closed 6 years ago

007scorpio commented 6 years ago

after given option to rerun with to gain shell access... it report parameters are not injectable

epinna commented 6 years ago

It can be anything, you gave me no data to evaluate. False positives are indeed possible, reproduce manually the working injection request and analyse yourself.