Page is a not externally linkable
- Microsoft
-- Microsoft IIS Web Server and ASP.NET
---- lilupophilupop SQL Injection Attack happening ATM


freejung - 12:03 am on Dec 8, 2011 (gmt 0)


Wow, that's a long string.

I should clarify my statement: PDO in general (not just xPDO, which is cooler for other reasons) uses parameterized queries and should be safe if used properly.

And I should say I haven't heard of anyone using MODX Revolution having problems with SQL or script injection. MODX Evolution, the earlier version, did have an SQL vulnerability at one point, but that was before they started using xPDO.

Generally speaking, whatever your language, you should use a framework that does parameterized queries as this has performance advantages in addition to being more secure.


Thread source:: http://www.webmasterworld.com/microsoft_asp_net/4394155.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com