CodeCharge Studio
search Register Login  

Web Reporting

Visually create Web Reports in PHP, ASP, .NET, Java, Perl and ColdFusion.
CodeCharge.com

YesSoftware Forums -> CodeCharge Studio -> General/Other

 PHP SQL Injection Bug - Update

Print topic Send  topic

Author Message
mentecky

Posts: 321
Posted: 01/19/2009, 2:55 AM

I have been messing with my recent PATCH a lot because I consider this critical and I can't wait for an official fix. I'm sure Yes will fix it and I'll get to remove the patch eventually, but I can't take the chance with my live sites.

My original patch seems solid and I have yet to have any issues with it, but in looking at the original CCS code and trying to guess the intention of it's design, I found that my first patch did not address every possible use of CCBuildSQL. Specifically if $where and $order_by both had values but only one was specified in the $sql query. My new PATCH addresses that also.

You can find it at:
http://ccselite.com/forums_topics_view.php?forum_id=2&forum_topic_id=41

It's in a post farther down the page.

Rick
_________________
http://www.ccselite.com
View profile  Send private message

Add new topic Subscribe to topic   


These are Community Forums for users to exchange information.
If you would like to obtain technical product help please visit http://support.yessoftware.com.

Internet Database

Visually create Web enabled database applications in minutes.
CodeCharge.com

Home   |    Search   |    Members   |    Register   |    Login


Powered by UltraApps Forum created with CodeCharge Studio
Copyright © 2003-2004 by UltraApps.com  and YesSoftware, Inc.