<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Tracmor Forum - Custom Field: SQL Injection]]></title>
		<link>http://www.tracmor.com/forum/topic/164/custom-field-sql-injection/</link>
		<description><![CDATA[The most recent posts in Custom Field: SQL Injection.]]></description>
		<lastBuildDate>Thu, 23 Jul 2009 18:36:05 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Custom Field: SQL Injection]]></title>
			<link>http://www.tracmor.com/forum/post/507/#p507</link>
			<description><![CDATA[<p>Thanks for reporting this.&nbsp; We are looking into it now.</p>]]></description>
			<author><![CDATA[null@example.com (jsinclair)]]></author>
			<pubDate>Thu, 23 Jul 2009 18:36:05 +0000</pubDate>
			<guid>http://www.tracmor.com/forum/post/507/#p507</guid>
		</item>
		<item>
			<title><![CDATA[Custom Field: SQL Injection]]></title>
			<link>http://www.tracmor.com/forum/post/504/#p504</link>
			<description><![CDATA[<p>1) Create new custom text area field &quot;sqlinject&quot;, tied to asset, enabled<br />2) ensure magic_quotes_gpc is turned off per <a href="http://www.tracmor.com/forum/topic/119/invalid-strip-slashes-needed/">http://www.tracmor.com/forum/topic/119/ … es-needed/</a> (restart if needed)<br />3) add new asset, use as input for sqlinject custom field {I&#039;d not type something like; drop table assets ; in this field} (sans curlies)<br />4) note error<br />5) rejoice</p><p>... unless I was updating said field.</p><p>tracmor 0.2.0; ubuntu intrepid/ standard apache2/php w/ php mem increased + magic_quotes_gpc off</p>]]></description>
			<author><![CDATA[null@example.com (oneshot)]]></author>
			<pubDate>Thu, 23 Jul 2009 04:03:30 +0000</pubDate>
			<guid>http://www.tracmor.com/forum/post/504/#p504</guid>
		</item>
	</channel>
</rss>

