Template:SQL injection alert/en: Difference between revisions
From Bonkipedia
[[mw:]]>FuzzyBot (Updating to match new version of source page) |
ManfredoDo (talk | contribs) m (1 revision imported: Template documentation pages) |
(No difference)
|
Latest revision as of 18:05, 12 November 2022
<translate> Warning:</translate> <translate> The code or configuration described here poses a major security risk.</translate> <translate> Site administrators:</translate> <translate> You are advised against using it until this security issue is resolved.</translate> <translate> Problem:</translate> Vulnerable to SQL injection attacks, because it passes user input directly into SQL commands. This may lead to user accounts being hijacked, wiki content being compromised, private data being leaked, malware being injected, and the entire wiki content being erased, among other things. <translate> Solution:</translate> make proper use of MediaWiki's database class instead of concatenating raw sql |
Template documentation
[create]