Volv
Skinning Contest Winner
    

Posts: 1233 Reputation: 31
36 / / 
Joined: Oct 2004
|
RE: Who knows something about SQL and PHP
quote: Originally posted by Chris Boulton
Not on the flash side of things, but I wanted to point out a major vulnerability your script has: SQL Injection.
You don't sanitize any quotes or anything before you insert raw data in to the database.
![[Image: exploits_of_a_mom.png]](http://imgs.xkcd.com/comics/exploits_of_a_mom.png)
|
|