Re: Open source project

From: Date: Tue, 02 Dec 2014 18:20:37 +0000
Subject: Re: Open source project
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-324078@lists.php.net to get a copy of this message
I see a problem here and please correct me if I'm wrong, as I have not actually tested this code. It appears that you are building your SQL queries directly from the POST data without any sanitation. This easily introduces SQL injection vulnerabilities into your code. In your case it looks like prepared statements aren't going to work, so I would suggest using a white-list of safe values and check against that. Even if this is meant only for a developer to use and not public facing, you should always assume the input is malicious and protect against it. Thanks, Derek On Mon, Dec 1, 2014 at 11:42 PM, Farzan Dalaee <farzan.dalaee@gmail.com> wrote: > Hi all > My open source tree view project on github > Feel free to use it > https://github.com/farzandalaee/FDTreeView > > Best Regards > Farzan Dalaee >

« previous php.general (#324078) next »