Improve : add a function for detection SQL inject
This commit is contained in:
parent
5911150677
commit
1666f570be
4 changed files with 49 additions and 5 deletions
|
|
@ -956,6 +956,24 @@ class DatabaseCore
|
|||
static function nb_column($p_ret) {
|
||||
return pg_num_fields($p_ret);
|
||||
}
|
||||
/**
|
||||
* FInd if a SQL Select has a SQL stmt to inject or damage Data
|
||||
* When a SELECT SQL string is build, this string could contain a SQL attempt to damage data,
|
||||
*so the statement DELETE TRUNCATE ... are forbidden. Throw an exception EXC_INVALID
|
||||
*
|
||||
*/
|
||||
function search_sql_inject($p_sql)
|
||||
{
|
||||
$forbid_sql=array("update","delete","truncate","insert");
|
||||
// protect against SQL inject
|
||||
foreach ($forbid_sql as $forbid_key) {
|
||||
if (stripos($p_sql,$forbid_key) !== false)
|
||||
{
|
||||
throw new Exception(_("Possible SQL inject",EXC_INVALID));
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue