BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Intresting case of SQL Injection Dec 04 2003 10:37PM
Markus Fischer (mfischer gjat josefine at)
On Thu, Dec 04, 2003 at 04:39:15PM -0300, Martin Sarsale (runa@sytes) wrote :
> Yesterday, we found an interesting case of SQL Injection.
[...]
> The main problem here was that developers where trusting in PHP auto
> escaping which worked in MySQL (and probably PostgreSQL) but not in MSSQL.

Th...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus