<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[Tracmor Forum - Custom Field: SQL Injection]]></title>
	<link rel="self" href="http://www.tracmor.com/forum/feed/atom/topic/164/"/>
	<updated>2009-07-23T18:36:05Z</updated>
	<generator>PunBB</generator>
	<id>http://www.tracmor.com/forum/topic/164/custom-field-sql-injection/</id>
		<entry>
			<title type="html"><![CDATA[Re: Custom Field: SQL Injection]]></title>
			<link rel="alternate" href="http://www.tracmor.com/forum/post/507/#p507"/>
			<content type="html"><![CDATA[<p>Thanks for reporting this.&nbsp; We are looking into it now.</p>]]></content>
			<author>
				<name><![CDATA[jsinclair]]></name>
				<uri>http://www.tracmor.com/forum/user/16/</uri>
			</author>
			<updated>2009-07-23T18:36:05Z</updated>
			<id>http://www.tracmor.com/forum/post/507/#p507</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Custom Field: SQL Injection]]></title>
			<link rel="alternate" href="http://www.tracmor.com/forum/post/504/#p504"/>
			<content type="html"><![CDATA[<p>1) Create new custom text area field &quot;sqlinject&quot;, tied to asset, enabled<br />2) ensure magic_quotes_gpc is turned off per <a href="http://www.tracmor.com/forum/topic/119/invalid-strip-slashes-needed/">http://www.tracmor.com/forum/topic/119/ … es-needed/</a> (restart if needed)<br />3) add new asset, use as input for sqlinject custom field {I&#039;d not type something like; drop table assets ; in this field} (sans curlies)<br />4) note error<br />5) rejoice</p><p>... unless I was updating said field.</p><p>tracmor 0.2.0; ubuntu intrepid/ standard apache2/php w/ php mem increased + magic_quotes_gpc off</p>]]></content>
			<author>
				<name><![CDATA[oneshot]]></name>
				<uri>http://www.tracmor.com/forum/user/148/</uri>
			</author>
			<updated>2009-07-23T04:03:30Z</updated>
			<id>http://www.tracmor.com/forum/post/504/#p504</id>
		</entry>
</feed>

