Re: Re: PHP 4.3.3RC3 Released
| From: | moshe doron | Date: | Thu, 14 Aug 2003 08:41:16 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3901@lists.php.net to get a copy of this message | ||
"Derick Rethans" <derick@php.net> wrote in message
news:Pine.LNX.4.53.0308140932320.12247@jdi.jdimedia.nl...
> On Thu, 14 Aug 2003, moshe doron wrote:
>
> > What about hacking somehow the sqlite library to disallow chained
queries
> > (or at least do it optionally)?
> >
> > This behavior is *huge* security hole, allow to the cracker drop ur
database
> > using simple select where query.
>
> How is this a security hole?
http://www.phpbuilder.com/mail/php-developer-list/2003022/0062.php
moshe