Welcome Guest, Not a member yet? Register   Sign In
permitted_uri_chars in application/config.php not working [serious vulnerability]
#9

[eluser]osci[/eluser]
[quote author="Keat Liang" date="1308262408"]
i suggest the limit function(active record) should using is_numeric() to validate the data.

since it SQL LIMIT only accept INT[/quote]

True. Checked at mysql docs and LIMIT can be non negative integer with the exception of prepared statements and stored programs, which don't imply for active record.


Messages In This Thread
permitted_uri_chars in application/config.php not working [serious vulnerability] - by El Forum - 06-16-2011, 11:38 AM



Theme © iAndrew 2016 - Forum software by © MyBB