Menu

#1 sql queries are vulnerable to sql injections

open
nobody
None
5
2009-11-15
2009-11-15
DonLorenzo
No

The SQL queries are build using the normal python string mechanisms and are therefore vulnerable to possible SQL injections.
As a fix the Queries should make use of the bindValue() mechanism.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB