the flexinode fields select and checkbox doesn't check the submitted values before inserting them in the sql clause, as an affect this allows sql injection in the clause.

patch attached

CommentFileSizeAuthor
flexinode_sql.patch1.48 KBfago

Comments

gerhard killesreiter’s picture

Status: Needs review » Active

committed to cvs. Setting to active. Check if it applies to HEAD as well.

fago’s picture

Status: Active » Fixed

chx has already commited a fix for head.

Anonymous’s picture

Status: Fixed » Closed (fixed)