[buddypress-trac] [BuddyPress] #1223: Filters in SQL without proper quote escaping

buddypress-trac at lists.automattic.com buddypress-trac at lists.automattic.com
Thu Oct 22 02:44:30 UTC 2009


#1223: Filters in SQL without proper quote escaping
-------------------------------------------------+--------------------------
Reporter:  rvenable                              |       Owner:  apeatling
    Type:  defect                                |      Status:  assigned 
Priority:  blocker                               |   Milestone:  1.1.2    
Keywords:  security, sql injection, needs-patch  |  
-------------------------------------------------+--------------------------
Changes (by Jason_JM):

 * cc: Jason_JM (added)
  * owner:  => apeatling
  * status:  new => assigned
  * priority:  critical => blocker


Comment:

 This absolutely must get fixed ***ASAP***

 I will take care of the rest of the criticals so Andy can work on this.

-- 
Ticket URL: <http://trac.buddypress.org/ticket/1223#comment:5>
BuddyPress <http://buddypress.org/>
BuddyPress


More information about the buddypress-trac mailing list