Bugtraq mailing list archives
Re: Re: Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities
From: Salvatore Fresta aka Drosophila <drosophilaxxx () gmail com>
Date: Mon, 16 Aug 2010 10:35:30 +0200
No, it isn't a good idea. You can use always Jrequest::getVar specifing the type (http://api.joomla.org/Joomla-Framework/Environment/JRequest.html#getVar). The allowed types are: INT, FLOAT, BOOLEAN, WORD, ALNUM, CMD, BASE64, STRING, ARRAY, PATH. Regards. -- Salvatore Fresta aka Drosophila http://www.salvatorefresta.net CWNP444351
Current thread:
- Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities Salvatore Fresta aka Drosophila (Aug 10)
- <Possible follow-ups>
- Re: Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities tibor . fogler (Aug 13)
- Re: Re: Amblog 1.0 Joomla Component Multiple SQL Injection Vulnerabilities Salvatore Fresta aka Drosophila (Aug 16)