Re: New builds posted to jdbc.postgresql.org websit for jdbc driver

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: New builds posted to jdbc.postgresql.org websit for jdbc driver
Дата
Msg-id 14424.1059013150@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: New builds posted to jdbc.postgresql.org websit for jdbc driver  (Oliver Jowett <oliver@opencloud.com>)
Список pgsql-jdbc
Oliver Jowett <oliver@opencloud.com> writes:
> On Wed, Jul 23, 2003 at 05:30:52PM -0700, Barry Lind wrote:
>> New 7.3 and Dev builds for the driver are posted to the website.  These
>> fix two additional sql injection vulnerabilities reported by Oliver
>> Jowett and Dmitry Tkach.

> Now that it's patched, the one I reported was that you could insert a
> literal \0 via setString() and friends, which the backend treated as "end of
> query", so you could use a string like this:

>   "\0Qrollback;begin;insert into testquerynull(sensitive) values (42);commit\0"

> to inject your own query.

FWIW, that won't work anymore in the V3 protocol, whether or not JDBC
has been patched to reject nulls ...

            regards, tom lane

В списке pgsql-jdbc по дате отправления:

Предыдущее
От: Barry Lind
Дата:
Сообщение: Re: psql and jdbc insert discrepencies
Следующее
От: Joe Conway
Дата:
Сообщение: Re: the IN clause saga