modzero / mod0BurpUploadScanner

HTTP file upload scanner for Burp Proxy
Other
479 stars 138 forks source link

Bug #80

Open z3dc0ps opened 3 years ago

z3dc0ps commented 3 years ago

Traceback (most recent call last):
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 981, in doActiveScan
    self.do_checks(injector)
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 1088, in do_checks
    self._php_rce(injector)
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 1088, in do_checks
    self._php_rce(injector)
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 1738, in _php_rce
    self._servercode_rce_gif_content(injector, lang, payload_exact_13_len, types)
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 2112, in _servercode_rce_gif_content
    self._send_simple(injector, types, basename, content, redownload=True)
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 4225, in _send_simple
    urrs.append(self._make_http_request(injector, req, redownload_filename=x))
  File "C:\Users\Administrator\AppData\Roaming\BurpSuite\bapps\b2244cbb6953442cb3c82fa0a0d908fa\UploadScanner.py", line 4380, in _make_http_request
    attack = self._callbacks.makeHttpRequest(service, req)
NullPointerException: java.lang.NullPointerException: Cannot read field "b" because the return value of "burp.fb0.f()" is null

Upload Scanner Version: 1.0.8

Extension code location: doActiveScan
Jython version: 2.7.2 (v2.7.2:925a3cc3b49d, Mar 21 2020, 10:03:58)
[Java HotSpot(TM) 64-Bit Server VM (Oracle Corporation)]
Java version: 15
Burp version: Burp Suite Professional 2020 9.2
Command line arguments: 
Was loaded from BApp: True
Request: