Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ScanQLi — SQLi scanner to detect SQL vulns | Kitploit
Tools/GitHubGitHub/bambish/scanqli
Vulnerability ScannersWeb SecurityPenetration Testing
GitHubbambish/scanqli

ScanQLi

SQLi scanner to detect SQL vulns

View Repository
2036417 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ScanQLi License Python 2|3 Twitter

Screenshot

ScanQLi is a simple SQL injection scanner with somes additionals features. This tool can't exploit the SQLi, it just detect them.

Tested on Debian 9

Features

  • Classic

  • Blind

  • Time based

  • GBK (soon)

  • Recursive scan (follow all hrefs of the scanned web site)

  • Cookies integration

  • Adjustable wait delay between requests

  • Ignore given URLs

Prerequisites

1. Install git tool.

root@kitploit:~
apt update
apt install git

2. Clone the repo.

root@kitploit:~
git clone https://github.com/bambish/ScanQLi

3. Install python required libs

root@kitploit:~
apt install python-pip
cd ScanQLi
pip install -r requirements.txt

For Python 3 please install python3-pip and use pip3.

Usage

root@kitploit:~
python scanqli -u [URL] [OPTIONS]

Examples

Simple URL scan with output file:

root@kitploit:~
python scanqli.py -u 'http://127.0.0.1/test/?p=news' -o output.log

Recursive URL scanning with cookies:

root@kitploit:~
python scanqli.py -u 'https://127.0.0.1/test/' -r -c '{"PHPSESSID":"4bn7uro8qq62ol4o667bejbqo3" , "Session":"Mzo6YWMwZGRmOWU2NWQ1N2I2YTU2YjI0NTMzODZjZDVkYjU="}'

Warning

ScanQLi was created to perform pentest or others legal stuffs (like bug bounty). Using ScanQLi against web site without authorization is forbidden.

I'm not responsible of your usage of ScanQLi. At your own risk.

Download Tool