Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0009074Openbravo ERPA. Platformpublic2009-05-18 15:342009-06-18 00:00
shuehner 
shuehner 
urgentmajorhave not tried
closedduplicate 
5
2.40 
 
Core
No
0009074: SQL injection in datagrid code
The datagrid code has issues where it is possible to inject code into the executed SQL statement via crafted parameters
No tags attached.
duplicate of defect 0009501 closed shuehner Audit all xsql to ensure that all xsql-parameters of type argument/replace are properly validated -part1 
related to defect 0008579 closed shuehner SQL injection in selectors 
depends on feature request 0009500 closed shuehner Add infrastructure to VariablesBase class to allow for technical validation of request parameters 
Issue History
2009-05-18 15:34shuehnerNew Issue
2009-05-18 15:34shuehnerAssigned To => rafaroda
2009-05-18 15:34shuehnerRegression testing => No
2009-05-18 15:34shuehnerRelationship addedrelated to 0008579
2009-05-20 12:05psarobeStatusnew => scheduled
2009-05-20 12:05psarobeAssigned Torafaroda => shuehner
2009-05-20 12:05psarobefix_in_branch => pi
2009-06-17 18:24shuehnerRelationship addeddepends on 0009500
2009-06-17 18:30shuehnerRelationship addedduplicate of 0009501
2009-06-17 18:30shuehnerStatusscheduled => closed
2009-06-17 18:30shuehnerNote Added: 0017395
2009-06-17 18:30shuehnerDuplicate ID0 => 9501
2009-06-17 18:30shuehnerResolutionopen => duplicate
2009-06-18 00:00anonymoussf_bug_id0 => 2807994

Notes
(0017395)
shuehner   
2009-06-17 18:30   
First commit into 9501 does include fix for this issue.