shop.php with empty query

  • Knut Krüger

    Knut Krüger - 2011-02-24

    Hi Matthias, hi Rick
    I changed my server
    suse 11.1 Vserver php 5.2.14 with suhosin extensions

    I am getting empty queries when logged in and using the  loup.
    This happens not with  all records.
    Any suggestions?

    Kind regards Knut

  • Knut Krüger

    Knut Krüger - 2011-02-25

    found it.

    suhosin: ALERT - configured GET variable value length limit exceeded - dropped variable 'sqlQuery' (attacker '', file '/srv/www/clients/client1/web6/web/refdb/search.php')

    Kind regards Knut

  • Knut Krüger

    Knut Krüger - 2011-02-25

    what do you think should be the minimum for php_value suhosin.get.max_value_length  ?


  • Richard Karnesky

    2000 characters is reasonable, given what those queries are doing & that this is still lower than the length that can be used in IE (and MUCH lower than in other browsers).  You can also change the queries to POSTs (though that is not without disadvantages (post confirmation, no ability to bookmark, etc.).


Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.

No, thanks