This repository has been archived by the owner on Dec 13, 2022. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 240
centstorage and backslash issue #1251
Milestone
Comments
Original Redmine Comment trunk => revision r12534 |
Original Redmine Comment branch 2.2.x => revision r12536 I'll leave this case open until validation |
Original Redmine Comment Max, Could you please proceed with a migration (2.1.x => 2.3.0) and make sure that metrics that contain #S# and #BS# are properly carried over and that CentStorage keeps graphing properly afterwards. Thanks :-) |
This was referenced Jan 22, 2024
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
None yet
0 participants
Author Name: Sylvestre Ho (Sylvestre Ho)
Original Redmine Issue: 2653, https://forge.centreon.com/issues/2653
Original Date: 2011-09-26
Original Assignee: Maximilien Bersoult
Hi,
There is no escaping method used in centstorage, could the door be opened to sql injections?
We should use quote methods as much as possible.
Also, the backslash issue doesn't seem to be solved as of version 2.2 and 2.3. Adding quote methods does solve the problem!
This change requires some solid testing before validation though.
The text was updated successfully, but these errors were encountered: