Beefy Boxes and Bandwidth Generously Provided by pair Networks
Just another Perl shrine
 
PerlMonks  

Re: Re: Sessions, Perl and MySQL

by runrig (Abbot)
on Mar 30, 2003 at 19:37 UTC ( [id://246762]=note: print w/replies, xml ) Need Help??


in reply to Re: Sessions, Perl and MySQL
in thread Sessions, Perl and MySQL

you are passing raw user input to your DB...
A serious concern here is that you can turn "where id = $something" into "where id = <anything> or 1=1" possibly letting anyone have admin access.

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://246762]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others surveying the Monastery: (7)
As of 2024-04-23 06:19 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found