Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

sqlmap

Automatic SQL injection and database takeover helper with fingerprinting, data exfiltration, and OS-shell paths.

Why it is included

Standard open tool for demonstrating and fixing SQLi in sanctioned tests.

Best for

Web pentesters validating injection classes after scope approval.

Strengths

  • Deep DB support
  • Tamper scripts
  • Enumeration depth

Limitations

  • Illegal and unethical outside written authorization

Good alternatives

OWASP ZAP · Manual validation

Related tools