Quote:
Originally Posted by nso
It won't. The strigns are escaped, and an attacker won't be able to perform sql-injections.
The error is that the . and : are appended, but they are not harmfull characters.
It could probably be solved by adding int() around the post-variable, or by using the in-built GPC(?) method in vbb
|
I Appreciate Your Answer
nso. :up:
Could
Coders Shack Please Confirm This Answer Provided by
nso?


I've Disabled the Product since some days ago Until
Coders Shack Answer to that Matter of SQL Injections.
My Best Regards.