Menu ▾ ▴

#7 CGI's are vulnerable to SQL injection

open
nobody
5
2003-10-07
2003-10-07
Rojer
No

no syntax checking is done on variables used in SQL
query construction.
this makes it possible to bypass authentication (e.g.
users.cgi)
with the following universal password:
" OR 1 OR id="

solution is to escape values before using them in SQL
queries.
(e.g. of $dbh->quote())

Discussion


Log in to post a comment.