Official archive + Python
RecommendedzipOfficialSQLMap ships as a pure-Python archive: download it, install Python 3, then run sqlmap.py.
- Install Python from python.org and tick 'Add to PATH'; the SQLite/PostgreSQL client libraries are optional.
Automated SQL injection detection engine
SQLMap detects and confirms SQL injection flaws by generating and sending probes, then reporting what the database reveals back. It is a verification tool: it turns a suspicious parameter into a reproducible finding — or rules the parameter out.
It can also enumerate schema, read limited files and, on some database configurations, execute further actions. Those capabilities are only appropriate inside a signed scope with a documented test plan; in a report, the enumeration of your own test data is the evidence, not an exploit demonstration.
Supported platforms
7
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
sql injection, database, web, verification, owasp
Dataset entry
sqlmap.ts
Reviewed 2026-01-12
Grouped by platform. Elevation requirements are marked per method.
SQLMap ships as a pure-Python archive: download it, install Python 3, then run sqlmap.py.
brew install sqlmap
sudo apt update
sudo apt install sqlmap
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git
python3 sqlmap/sqlmap.py --version
Package availability follows your distribution and enabled repositories. Entry revised 12 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Runs detection techniques against a single GET parameter and reports which ones produced a true/false differential.
python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --batch --level 1 --risk 1
Notes
Confirms backend DBMS, version and operating system as reported through the injection point.
python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --banner --batch
Example output
Illustrative only — real output depends on the target, version and your position on the network.
[INFO] the back-end DBMS is MySQL back-end DBMS: MySQL >= 8.0
Notes
Lists schemas visible to the connection the application uses.
python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --dbs --batch --dbms mysql
Notes
Proves read access with the smallest possible sample instead of exfiltrating a table.
python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id -D appdb -T users -C id,username --start 1 --count 5 --batch
Notes
Feeds a raw HTTP request file so headers, cookies, CSRF tokens and JSON bodies are used exactly as captured.
python3 sqlmap.py -r login.req --batch --forms
Notes
Applies encoding transformations to probes so you can see whether an input filter is actually mitigating the flaw.
python3 sqlmap.py -u 'http://192.0.2.20/search?q=sock' -p q --tamper=space2comment,between --batch
Notes
Works through a list of URLs rather than one parameter, which is how a whole application gets covered.
python3 sqlmap.py -m urls.txt --batch --threads 2 --delay 1
Notes
Clears the per-URL cache so retests do not silently reuse yesterday's conclusion.
python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' --flush-session --batch
Notes
Sequences of commands in the order they are used, with what you should expect to learn from each.
A 'Ref' parameter in a partner portal echoes a SQL error when you type a quote.
Confirm with the minimum detection level
python3 sqlmap.py -r ref.req -p Ref --batch --level 1 --risk 1
Establish what is reachable, without reading user data
python3 sqlmap.py -r ref.req -p Ref --banner --current-user --current-db --batch
Retest after the patch, with a clean session
python3 sqlmap.py -r ref.req -p Ref --flush-session --batch --level 1
A finding with an exact reproduction, an impact statement grounded in what was actually reachable, and a verified retest.
Remove ambiguity from a manual test before it reaches a report.
Re-run the same probes after remediation and keep both outputs.
Understand how blind and error-based detection differ, against deliberately vulnerable apps.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Re-save the request with a fresh cookie, raise `--level 3 --risk 2`, add `--no-redirect` or `--ignore-redirects` as appropriate, and confirm the session with `--safe-url`.
Possible causes
Usual fix
Add `--delay`, `--timeout`, `--retries`, and lower `--threads`. If the WAF is the control under test, document that it blocked the tool rather than working around it without approval.
python3 sqlmap.py -u URL -p id --batch --delay 2 --timeout 30 --threads 1
Possible causes
Usual fix
Use `--flush-session` for a retest, or `--purge-output` to clear the whole directory at engagement end.
Possible causes
Usual fix
Run with `python3` explicitly and install a current upstream checkout.
Not documented yet: sqlmap has no drop-in equivalent for automated verification; manual testing plus a proxy remains the primary method. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.