Menu

#4042 SQL Injection with Passwords

closed-fixed
nobody
None
5
2012-01-22
2012-01-21
Mr. Gecko
No

The passwords do not get escaped. Therefore, when I use my password which has an ' character in it, it errors out saying syntax error near my password. This is annoying because that's my password and it means anyone who has an account can change their password to inject sql.

This is on postgresql using virtual min to create the account.

Discussion

  • Jamie Cameron

    Jamie Cameron - 2012-01-22
    • status: open --> closed-fixed
     
  • Jamie Cameron

    Jamie Cameron - 2012-01-22

    Thanks for pointing this out .. this will be fixed in the next Virtualmin release.

     

Log in to post a comment.

MongoDB Logo MongoDB