Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
1 Registered (jacampbe), 20 Guests and 23 Spiders online.
Key: Admin, Global Mod, Mod
Top Posters
Gizmo 11708
Rick 7567
Ian 4107
Mark S 3984
ntdoc 3114
Sirdude 2041
jgeoff 1882
David Dreezer 1759
driv 1569
AllenAyres 1530
Latest Photos
Carrie - So Very
Testing
Test Photo
4TH of July at the river!
Test shots from D300 part 3
Topic Options
Rate This Topic
#213165 - 05/21/08 09:07 AM SQL Injection
jmt123 Offline
stranger

Registered: 05/17/08
Posts: 10
Is anyone here familiar with SQL Injection and is UBB Threads vulnerable?

Top
#213168 - 05/21/08 09:16 AM Re: SQL Injection [Re: jmt123]
Rick Administrator Offline

*****

Registered: 06/04/06
Posts: 7567
Loc: Aberdeen, WA
Yes. In the past UBB.threads had several vulnerabilities during different stages. Generally, this was related to forgetting to call addslashes and sanitize all data coming from the user.

When we rewrote version 7 however we now pass everything through a variety of functions that take care of this. All of our sql queries go through a routine where we pass the user data in an array, and each one is sanitized/escaped properly before actually being passed to MySQL. So we haven't had an issue with this since 7.0 came out.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top


Shout Box

Recent Topics
Registration security
by adminwendy
Yesterday at 09:33 PM
Problem with forum move
by AzHousePro
Yesterday at 03:41 PM
[7.3.x] Ignore link showed in userprofile for global moderators
by blaaskaak
09/06/08 01:27 PM
[7.3.x] Database password shown in adminlogs...
by blaaskaak
09/06/08 10:24 AM
7.3.1 Flood protection
by MattUK
09/06/08 03:55 AM
Forum Stats
4027 Members
33 Forums
30887 Topics
156842 Posts

Max Online: 978 @ 06/24/07 08:19 PM