Menu ▾ ▴

#3 Security: SQL Injection prone

open
nobody
None
5
2008-03-31
2008-03-31
GingerDog
No

If you go to a URL like :

/ppm_account_view.php?id='1

You see :

query failed: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1' at line 1

Hence, it's open to SQL injection vulnerabilities.

Discussion

  • leprasmurf

    leprasmurf - 2008-05-29

    Logged In: YES
    user_id=1293131
    Originator: NO

    looks like you may be correct, as far as I can find the class simply adds the value to the sql statement before executing. Try surrounding all instances of $_POST or $_GET with htmlentities().

     
  • leprasmurf

    leprasmurf - 2008-05-29

    Logged In: YES
    user_id=1293131
    Originator: NO

    Correction, use mysql_real_escape_string()

     

Log in to post a comment.