Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 294363

orderby() should verify direction [DONE] and escape fields

$
0
0

In my dream (where unicorns also roam) DBTNG goes out of its way to prevent SQL injections due to silly mistakes, or a moment of carelessness.

orderby() doesn't escape fields / aliases and does not check $direction, allowing SQL injection when developers pass usersupplied data.

idem for group by, though that needs further study.


Viewing all articles
Browse latest Browse all 294363

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>