Opened 13 years ago

Closed 13 years ago

#544 closed defect (fixed)

Get User SQL injection potential

Reported by: jesseeichar Owned by: geonetwork-devel@…
Priority: critical Milestone: v2.6.5
Component: General Version: v2.6.3
Keywords: Cc:

Description

Get passes the id parameter directly to the SQL which is potential SQL injection attack. Attached is a patch for a fix

Attachments (1)

getuserSqlInjectionPatch.patch (1.6 KB ) - added by jesseeichar 13 years ago.

Download all attachments as: .zip

Change History (2)

by jesseeichar, 13 years ago

comment:1 by josegar74, 13 years ago

Resolution: fixed
Status: newclosed
Note: See TracTickets for help on using tickets.