Possible SQL Injection
-
In function duplicate_post_get_current_user() used unfiltered $_COOKIE variable:
$user_login = $_COOKIE[USER_COOKIE]; $current_user = $wpdb->get_results("SELECT * FROM $wpdb->users WHERE user_login='$user_login'");
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Possible SQL Injection’ is closed to new replies.