MySQL Security

MySQL Security News, Articles, and Blogs

XSS inside script tags

Published by | Filed under check, apple, manual, corresponds, syntax, error, server, version, injection, mysql

Update:. Ronald found an SQL injection on Apple’s site. Here is the SQL injection. You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘15? at line 30.
applications commands database databases injection modified […]

June 21st, 2007. Comment now »

Web Wiz Forums v.8.05 (MySQL version) SQL Injection Security …

Input passed to the “name” parameter in “pop_up_member_search.asp” isn’t properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Confirmed in version 1.1.4. …
Read the original: Web Wiz Forums v.8.05 (MySQL version) SQL Injection Security …
arbitrary confirmed exploited injecting […]

May 23rd, 2007. Comment now »

Rails’ friends: Securing MySQL

Published by Admin | Filed under secure, storage, setups, machine, version, server, rails, mysql

Many Rails setups use MySQL as back-end storage. So let’s set up a secure MySQL server, which will run on the same machine as Ruby on Rails and the web server. In the following we will be using MySQL version 5.0 on a Unix system. …
Originally posted here: Railsâ?? friends: Securing MySQL
machine mysql […]

February 25th, 2007. Comment now »


Register Domains | Windows Security Blogs | repaid.us


Cheap Web Hosting