https://bugzilla.wikimedia.org/show_bug.cgi?id=19621





--- Comment #4 from Al Maghi <alfred.ma...@gmail.com>  2009-07-14 12:31:53 UTC 
---
(In reply to comment #3)
> That shouldn't work. If it does, that's an SQL injection vulnerability.
> 

Is it not rather a selection than an injection; indeed that query does not
change the DB:

'SELECT ... FROM ... WHERE rev_page=page_id AND page_namespace=0 AND
page_is_redirect=0'


-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to