Loading...
Loading...
PHP Web Source Code SQL Injection Vulnerability Audit Tool. Identify all SQL execution points from the source code, analyze injection risks, and output exploitability grading, PoC, and repair suggestions (no omissions allowed).
npx skill4agent add 0xshe/php-code-audit-skill php-sql-auditshared/SEVERITY_RATING.md{C/H/M/L}-SQL-{serial number}shared/IO_PATH_CONVENTION.mdroutes_{timestamp}.mdroute_mapping/routes_{timestamp}.mdparams_{timestamp}.mdroute_mapping/params_{timestamp}.mdroute_tracer/$pdo->query($sql)$pdo->exec($sql)$pdo->prepare($sql)$sqlbindParam/bindValueDB::select(DB::raw({value}))createQuerymysqli_query($conn, $sql)mysqli_prepare.sprintfvsprintfimplode/joinorder by $xORDER BY \".$x.\"php-route-tracer{output_path}/vuln_audit/
└── sql_{timestamp}.md### [{Severity Prefix}-SQL-{Serial Number}] {Risk Title}
| Item | Information |
|------|------|
| Severity Level | {🔴/🟠/🟡/🔵} (CVSS {score}) |
| Reachability (R) | {0-3} - {Reason} |
| Impact Scope (I) | {0-3} - {Reason} |
| Exploit Complexity (C) | {0-3} - {Reason} |
| Exploitability | ✅ Confirmed / ⚠️ Pending Verification / ❌ Not Exploitable / 🔍 Environment Dependent |
| Location | {file}:{line} ({Function/Class}) |
#### Data Flow Chain (Source → Sink)
(Write line by line by route: Request parameter reading -> Variable assignment/concatenation/conversion -> Branch -> SQL enters execution point. No omissions allowed)
#### Preconditions for Exploitation
- Authentication Requirements: {None/Login Required/Specific Permission Required}
- Input Controllability: {Fully Controllable/Conditionally Controllable/Uncontrollable}
- Trigger Conditions: {Branch/Exception/Environment Dependence}
#### Evidence Reference (Mandatory: from php-route-tracer)
Each suspected SQL vulnerability must reference the corresponding key points of the **SQL line** in `## 9) Sink Evidence Type Checklist` from the trace output (status can be pending verification, but evidence reference must exist):
1. `EVID_SQL_EXEC_POINT`: SQL execution function/statement location (corresponding to the SQL execution point evidence of the trace)
2. `EVID_SQL_STRING_CONSTRUCTION`: SQL string construction/concatenation location (corresponding to the SQL concatenation evidence of the trace)
3. `EVID_SQL_USER_PARAM_TO_SQL_FRAGMENT`: Mapping of user-controllable parameters to SQL fragments (corresponding to the controllability matrix field evidence of the trace)
#### Handling Missing Tracer Evidence (Mandatory)
- If any of the key evidence points 1~3 above cannot be located: The vulnerability status can only be marked as `⚠️Pending Verification`, and `✅Confirmed Exploitable` cannot be directly given.
#### Verification PoC (Mandatory, Executable Request)
```http
{HTTP Method} {Full Path and Query/Body} HTTP/1.1
Host: {host}
{Necessary Header/Session/JWT/Cookie}
{Payload}rggrep
## Output Completeness Check (Mandatory)
- [ ] At least output: Risk statistics + complete entries for each vulnerability
- [ ] No omission placeholders appear
- [ ] Each vulnerability includes: Data flow chain, preconditions for exploitation, executable PoC, repair suggestions",