![]() |
|
SQL injection in /rss.php - Printable Version +- ZenphotoCMS Forum (https://forum.zenphoto.org) +-- Forum: Support (https://forum.zenphoto.org/forum-1.html) +--- Forum: General support (https://forum.zenphoto.org/forum-4.html) +--- Thread: SQL injection in /rss.php (/thread-6838.html) |
SQL injection in /rss.php - weweje - 2010-03-28 Hi, rss.php is vulnerable to sql injection via SQL injection in /rss.php - acrylian - 2010-03-28 I actually don't think as these query parameter values are sanitized via our SQL injection in /rss.php - weweje - 2010-03-28 zenphoto version 1.2.9 [5088]
SQL injection in /rss.php - acrylian - 2010-03-28 But that does no harm if the values make no sense to Zenphoto and just throws that error. SQL injection in /rss.php - acrylian - 2010-03-28 We double checked that and you are actually right. So fix will be in tonight's nightly. |