lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20040216210518.10459.qmail@www.securityfocus.com> Date: 16 Feb 2004 21:05:18 -0000 From: Mike Bobbitt <mike@...y.ca> To: bugtraq@...urityfocus.com Subject: Re: Another YabbSE SQL Injection In-Reply-To: <002a01c3f4c3$d6eecc40$381e5a0a@...anet69> Correction... the code change needs to be as follows: Find: $quotemsg = $quote; Change to: if ( $quote && !is_numeric($quote) ) { die('Go out C==|=======>'); } $quotemsg = $quote; ---- Otherwise you won't be able to use the standard reply button. Cheers and thanks for the info.