Re: sybase_ct batch query security issue

From: Date: Wed, 19 Feb 2003 21:10:39 +0000
Subject: Re: sybase_ct batch query security issue
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-94370@lists.php.net to get a copy of this message
On Tue, 2003-02-18 at 20:24, moshe doron wrote: > there is security case here e.g, allowing the cracker chain "DELETE FROM X" to > "SELECT * FROM X WHERE ID=$id" where the $id is got via the url without > checking (most of the cases). You're right - thanks for mentioning this. - Timm

« previous php.dev (#94370) next »