PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Classifieds Support > Classifieds How do I...?

Classifieds How do I...? Wondering how to do something in Classifieds?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old July 18th, 2011, 12:59 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Oct 2005
Posts: 119
An error was encountered: MySQL injection?

Hello Chuck,

is the following error known? We got this today for the first time:


An error was encountered during execution of the query:

SELECT id,cat FROM pp_products WHERE approved=1 AND ((title LIKE "% !S!WCRTESTINPUT000000!E!%" OR description LIKE "% !S!WCRTESTINPUT000000!E!%" OR keywords LIKE "% !S!WCRTESTINPUT000000!E!%" OR bigimage LIKE "% !S!WCRTESTINPUT000000!E!%"
OR extra1 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra2 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra3 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra4 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra5 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra6 LIKE "% !S!WCRTESTINPUT000000!E!%") OR (title LIKE "!S!WCRTESTINPUT000000!E!%" OR description LIKE "!S!WCRTESTINPUT000000!E!%" OR keywords LIKE "!S!WCRTESTINPUT000000!E!%" OR bigimage LIKE "!S!WCRTESTINPUT000000!E!%"
OR extra1 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra2 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra3 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra4 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra5 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra6 LIKE "%!S!WCRTESTINPUT000000!E!%")) AND (user LIKE '%!S!WCRTESTINPUT000001!E!%') AND price >= 0.00 AND price


Thanks

Klaus
klaush is offline   Reply With Quote
Old July 18th, 2011, 02:33 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,699
Can you post the full error seems yours is cut off in mid stream
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old July 18th, 2011, 02:50 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Oct 2005
Posts: 119
Thatīs the whole message, Chuck.

Greeting

Klaus
klaush is offline   Reply With Quote
Old July 18th, 2011, 02:51 PM   #4 (permalink)
Member
Verified Customer
 
Join Date: Oct 2005
Posts: 119
Just got another one:

An error was encountered during execution of the query:

SELECT id,cat FROM pp_products WHERE approved=1 AND ((title LIKE "% !S!WCRTESTINPUT000000!E!%" OR description LIKE "% !S!WCRTESTINPUT000000!E!%" OR keywords LIKE "% !S!WCRTESTINPUT000000!E!%" OR bigimage LIKE "% !S!WCRTESTINPUT000000!E!%"
OR extra1 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra2 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra3 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra4 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra5 LIKE "% !S!WCRTESTINPUT000000!E!%" OR extra6 LIKE "% !S!WCRTESTINPUT000000!E!%") OR (title LIKE "!S!WCRTESTINPUT000000!E!%" OR description LIKE "!S!WCRTESTINPUT000000!E!%" OR keywords LIKE "!S!WCRTESTINPUT000000!E!%" OR bigimage LIKE "!S!WCRTESTINPUT000000!E!%"
OR extra1 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra2 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra3 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra4 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra5 LIKE "%!S!WCRTESTINPUT000000!E!%" OR extra6 LIKE "%!S!WCRTESTINPUT000000!E!%")) AND (user LIKE '%!S!WCRTESTINPUT000001!E!%') AND price >= !S!WCRTESTINPUT000007%3c%3e!E! AND price
klaush is offline   Reply With Quote
Old July 18th, 2011, 03:06 PM   #5 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,699
Maybe try altering your search script the typecast line low and high make sure they are set to INT not STRING?

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old July 18th, 2011, 03:56 PM   #6 (permalink)
Member
Verified Customer
 
Join Date: Oct 2005
Posts: 119
Sorry Chuck, where do i find this and what do you exaxtly mean by that?

Greetings

Klaus

Quote:
Originally Posted by Chuck S View Post
Maybe try altering your search script the typecast line low and high make sure they are set to INT not STRING?

Code:
Content visible to verified customers only.
klaush is offline   Reply With Quote
Old July 18th, 2011, 05:41 PM   #7 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,699
At the top of your search.php script in your classifieds directory.

You will see the typecast line I noted and make sure as in bold you use INT not STRING.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
An error was encountered klaush Classifieds Bug Reports 11 March 21st, 2011 01:00 PM
An error was encountered during execution of the query softsingapore Classifieds Bug Reports 1 July 9th, 2010 09:14 AM
An error was encountered during execution of the query ccaldwell Photopost Pro Installation & Upgrades 8 May 9th, 2008 11:03 AM
Security Alert: XSS and MySQL injection flaws c0bra General Discussion 8 March 29th, 2005 03:53 PM
error was encountered during execution of the query cnczone Photopost Pro Installation & Upgrades 13 July 24th, 2004 11:19 AM


All times are GMT -5. The time now is 07:23 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0