Re: sybase_ct batch query security issue
| From: | Timm Friebe | Date: | Wed, 19 Feb 2003 21:10:39 +0000 |
| Subject: | Re: sybase_ct batch query security issue | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-94370@lists.php.net to get a copy of this message | ||
On Tue, 2003-02-18 at 20:24, moshe doron wrote:
> there is security case here e.g, allowing the cracker chain "DELETE FROM X" to
> "SELECT * FROM X WHERE ID=$id" where the $id is got via the url without
> checking (most of the cases).
You're right - thanks for mentioning this.
- Timm