Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0009577Openbravo ERPZ. Otherspublic2009-06-22 11:382011-10-28 18:56
shuehner 
iciordia 
urgentmajorhave not tried
closedno change required 
5
pi 
 
Core
No
0009577: Audit all xsql to ensure that all xsql-parameters of type argument/replace are properly validated - part2
All xsql parameters of type argument/replace are potential candidates for injection sql code into the query. The code should be audited to ensure that the parameters' value have been properly validated by the callers.
No tags attached.
related to defect 0009501 closed shuehner Audit all xsql to ensure that all xsql-parameters of type argument/replace are properly validated -part1 
Issue History
2009-06-22 11:38shuehnerNew Issue
2009-06-22 11:38shuehnerAssigned To => rafaroda
2009-06-22 11:38shuehnerIssue generated from0009501
2009-06-22 11:38shuehnerRelationship addedrelated to 0009501
2009-06-29 13:25psarobeStatusnew => scheduled
2009-06-29 13:25psarobeAssigned Torafaroda => shuehner
2009-06-29 13:25psarobefix_in_branch => pi
2009-06-30 13:40psarobeAssigned Toshuehner => rafaroda
2009-06-30 13:40psarobefix_in_branchpi =>
2009-07-10 16:43pjuvaraPriorityimmediate => urgent
2010-02-11 18:05rafarodaAssigned Torafaroda => adrianromero
2011-06-03 11:00dalsasuaAssigned Toadrianromero => dalsasua
2011-07-20 18:11dalsasuaAssigned Todalsasua => jonalegriaesarte
2011-10-28 18:15psarobeAssigned Tojonalegriaesarte => iciordia
2011-10-28 18:56iciordiaNote Added: 0042294
2011-10-28 18:56iciordiaStatusscheduled => closed
2011-10-28 18:56iciordiaResolutionopen => no change required

Notes
(0042294)
iciordia   
2011-10-28 18:56   
xsql mechanism is being discontinued and replaced by DAL.