Closed Bug 491758 Opened 16 years ago Closed 16 years ago

SQL injection possible when editing collections

Categories

(addons.mozilla.org Graveyard :: Collections, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: clouserw, Assigned: lorchard)

Details

If you click "edit" on a collection and put a single quote into either the name or description the query fails with a parse error.
Did you confirm this on the code base from bug 456132? If it's not present there, this bug is invalid.
I used current trunk. Maybe I'm getting ahead of myself.
Yes, sorry ;) But you can volunteer to review bug 456132? I am sure Ryan wouldn't mind you doing that single-handedly, so to speak.
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → INVALID
PS: I hope that pun wasn't "too soon" ;)
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.