Menu

#2232 Posible SQL injection?

Can't Reproduce
closed
nobody
Folders (317)
5
2006-09-14
2006-08-28
brifcor
No

version 1.4.5 folders_create.php

POST /src/folders_create.php
folder_name=%27&subfolder=INBOX.Trash

------------

ERROR:
ERROR: Could not complete request.
Query: CREATE "INBOX.Trash/'"
Reason Given: Invalid mailbox name

------------

Discussion

  • Tomas Kuliavas

    Tomas Kuliavas - 2006-08-28

    Logged In: YES
    user_id=225877

    Please make sure that you can reproduce issue in 1.4.8.
    SquirrelMail 1.4.5 version is very old and newer versions
    have lots of fixes that fix html sanitizing.

    How does invalid mailbox name error lead to SQL injection?

     
  • Tomas Kuliavas

    Tomas Kuliavas - 2006-08-30
    • status: open --> pending
     
  • Tomas Kuliavas

    Tomas Kuliavas - 2006-08-30

    Logged In: YES
    user_id=225877

    Please provide more information about your issue or tracker
    will close.

    It is impossible to understand your problem if you pop short
    notice about something and ignore questions about it.

     
  • SourceForge Robot

    Logged In: YES
    user_id=1312539

    This Tracker item was closed automatically by the system. It was
    previously set to a Pending status, and the original submitter
    did not respond within 14 days (the time period specified by
    the administrator of this Tracker).

     
  • SourceForge Robot

    • status: pending --> closed
     

Log in to post a comment.