Linked by Thom Holwerda on Thu 5th Oct 2006 09:09 UTC, submitted by osnewsuser
Thread beginning with comment 168814
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.




Member since:
2005-06-29
While I don't agree with NotParker that black hats will use this to put intrusions in code hoping others will use it, I do think this could be relatively bad for web based applications. Simple search for "Where $_POST" with php as the language could result in some amazing SQL injection opportunities.
Then you know which project has them and all you have to do is find someone that utilizes that project (which isn't hard, you can do web servers for page names, etc).
http://www.google.com/codesearch?hl=en&lr=&q=Where+%5C%24_P...