[buddypress-trac] [BuddyPress] #1223: Filters in SQL without proper quote escaping (was: Filters are often used in SQL without proper quote escaping (possible injection vulnerability))

buddypress-trac at lists.automattic.com buddypress-trac at lists.automattic.com
Wed Oct 21 14:06:02 UTC 2009


#1223: Filters in SQL without proper quote escaping
---------------------------------------+------------------------------------
Reporter:  rvenable                    |       Owner:       
    Type:  defect                      |      Status:  new  
Priority:  critical                    |   Milestone:  1.1.2
Keywords:  sql injection, needs-patch  |  
---------------------------------------+------------------------------------

-- 
Ticket URL: <http://trac.buddypress.org/ticket/1223#comment:3>
BuddyPress <http://buddypress.org/>
BuddyPress


More information about the buddypress-trac mailing list