Login
Register
All class groups
Latest entries
Top 10 charts
Blog
Forums
Shop
Help
Login
Register
SQL injection vulnerability
Search
All class groups
Latest entries
Top 10 charts
Blog
Forums
Shop
Help
Recommend
this page to a friend!
Day Tips Show
>
All threads
>
SQL injection vulnerability
>
(Un) Subscribe thread alerts
Subject:
SQL injection vulnerability
Summary:
no escaping of _POST data
Messages:
1
Author:
Martin Pircher
Date:
2011-10-03 08:45:51
1. SQL injection vulnerability
Reply
Report abuse
Martin Pircher - 2011-10-03 08:45:51
insert.php
$content=$_POST['content'];
$writer=$_POST['writer'];
replace with:
$content=mysql_real_escape_string($_POST['content']);
$writer=mysql_real_escape_string($_POST['writer']);
About us
Advertise on this site
Site map
Newsletter
Statistics
Site tips
Privacy policy
Contact
Copyright (c)
Icontem
1999-2025
For more information send a message to
info at phpclasses dot org
.
image/svg+xml
image/svg+xml
Contact us using Messenger