Thanks, I'll give it a try.try https://github.com/r0oth3x49/ghauri
tamper= appendnullbyte,base64encode,randomcase
and try your cookie from web request put in sqlmap or ghauri
or try to dump manual with hackbar
--headers=”X-Forwarded-For: *”
--flush-session
A question not quite on the topic , is not ghauri just a clone of sqlmap ? Can you tell me more about this tool and its differences from sqlmap ?