CGI's are vulnerable to SQL injection
Brought to you by:
bradrathbun,
chris_joyce
no syntax checking is done on variables used in SQL
query construction.
this makes it possible to bypass authentication (e.g.
users.cgi)
with the following universal password:
" OR 1 OR id="
solution is to escape values before using them in SQL
queries.
(e.g. of $dbh->quote())