sybase_ct batch query security issue
| From: | moshe doron | Date: | Tue, 18 Feb 2003 19:24:46 +0000 |
| Subject: | sybase_ct batch query security issue | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-94327@lists.php.net to get a copy of this message | ||
there is security case here e.g, allowing the cracker chain "DELETE FROM X" to
"SELECT * FROM X WHERE ID=$id" where the $id is got via the url without checking (most of
the cases).
limiting the feature by optional parameter may needed.
--
"Timm Friebe" <thekid@thekid.de> wrote in message news:1045250219.49462.84.camel@localhost...
> On Fri, 2003-02-14 at 14:37, Michael Ulbrich wrote:
> > Hi there,
> Hi,
>
> > here's a small patch for sybase_query() in ext/sybase_ct.c which gives
> > some extended functionality in that it allows to send batch queries from
> > php to the Sybase backend.
> I'll have a look at it as soon as possible.
>
> Hello from Karlsruhe to Berlin:) - Timm
>