Download & Extend

sql injection in search_clause possible

Project:Flexinode
Version:4.6.x-1.x-dev
Component:Code
Category:bug report
Priority:critical
Assigned:Unassigned
Status:closed (fixed)

Issue Summary

the flexinode fields select and checkbox doesn't check the submitted values before inserting them in the sql clause, as an affect this allows sql injection in the clause.

patch attached

AttachmentSize
flexinode_sql.patch1.48 KB

Comments

#1

Status:needs review» active

committed to cvs. Setting to active. Check if it applies to HEAD as well.

#2

Status:active» fixed

chx has already commited a fix for head.

#3

Status:fixed» closed (fixed)
nobody click here