PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > ReviewPost Pro Support Forums > ReviewPost How do I...?

ReviewPost How do I...? Wondering how to do something in ReviewPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old June 6th, 2012, 12:33 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: May 2006
Location: Toronto
Posts: 205
Possible SQL Injection - How to protect?

Hi Chuck -

This is Yazmin under Zig's account again.

We just received the following error report:

Quote:
An error was encountered during execution of the query:

SELECT r.id,r.username,r.userid,r.date,r.review,r.cat,r.product,p.bigimage,p.cat,p.userid FROM rp_reviews r
LEFT JOIN rp_products p ON p.id=r.product WHERE r.review != '' AND r.cat IN (-1\\\') AND ((r.review LIKE "% 1%") OR (r.review LIKE "1%")) AND (r.username LIKE '%1%') AND r.date > 1338900045

The query returned with an errorcode of:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\\\') AND ((r.review LIKE "% 1%") OR (r.review LIKE "1%")) AND (r.username LIKE' at line 2
Seems like an injection attack. Anything we should be concerned with at this point?

Thanks.
Zigw is offline   Reply With Quote
Old June 6th, 2012, 01:50 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,692
I do not see any such query in our program like this.

I did a search for

Quote:
SELECT r.id,r.username,r.userid,r.date,r.review,r.cat,r.product,p.bigimage,p.cat,p.userid
I have searched for even smaller variations seems maybe whatever this is is some custom code you did somewhere outside the supported application.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old June 6th, 2012, 04:59 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: May 2006
Location: Toronto
Posts: 205
We're still working on getting our 3.3 version upgraded, which might explain why you aren't finding it. I found it in our search.php file.

Thanks.
Zigw is offline   Reply With Quote
Old June 6th, 2012, 05:14 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,692
Yeah I am looking at at 5.21
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Potential SQL Injection WB General Discussion 19 April 30th, 2010 05:34 AM
Can you password protect a category? jilly Photopost Pro How Do I...? 1 January 25th, 2008 10:51 PM
PP5.5 - sql injection attempts ! flat Photopost Pro Bug Reports 6 November 4th, 2006 06:17 AM
How do I Protect Config-inc.php? creativepart Classifieds How do I...? 11 July 31st, 2006 09:23 AM
sql injection attacks stmpspaz General Discussion 1 July 3rd, 2004 09:55 AM


All times are GMT -5. The time now is 10:38 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0