sybase_ct batch query security issue

From: Date: Tue, 18 Feb 2003 19:24:46 +0000
Subject: sybase_ct batch query security issue
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-94327@lists.php.net to get a copy of this message
there is security case here e.g, allowing the cracker chain "DELETE FROM X" to "SELECT * FROM X WHERE ID=$id" where the $id is got via the url without checking (most of the cases). limiting the feature by optional parameter may needed. -- "Timm Friebe" <thekid@thekid.de> wrote in message news:1045250219.49462.84.camel@localhost... > On Fri, 2003-02-14 at 14:37, Michael Ulbrich wrote: > > Hi there, > Hi, > > > here's a small patch for sybase_query() in ext/sybase_ct.c which gives > > some extended functionality in that it allows to send batch queries from > > php to the Sybase backend. > I'll have a look at it as soon as possible. > > Hello from Karlsruhe to Berlin:) - Timm >

« previous php.dev (#94327) next »