This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Sentora - General Security Warning ?
#19
RE: Sentora - General Security Warning ?
(03-20-2015, 04:14 AM)KwiceroLTD Wrote: [...]
There are multiple, MULTIPLE issues in this, and I don't even do auditing for a living or as a hobby.



Code:
$sql = $zdbh->prepare("INSERT INTO $database.$table_name $insert");
[...]

I agree it can better written, but .... the real question is : " are $database, $table and $insert reachable from an user ? "
The response isĀ  no : they are even not reachable at all !!!!

This code is extracted from the class db_builder. If you look a bit better with good search tool, you will see that this class is NEVER called !

I do not know from where (or from when) it comes, but it is an outdated class that can be removed. More, from its content, I discovers that it was intended to read and build a database from an XML file.
-> I am pretty sure that it was NEVER callable from the internet side, and I suppose strongly that it was a tool intended to be used from zppy or something like it (module setup ?).

So, please do not worry about this file or any of its (bad) content !
Reply
Thanks given by:


Messages In This Thread
Sentora - General Security Warning ? - by Active8 - 03-19-2015, 02:06 AM
RE: Sentora - General Security Warning ? - by 5050 - 03-21-2015, 06:28 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
Can anyone suggest best Sentora alternative servermaster 1 585 12-22-2023, 10:41 AM
Last Post: TGates
Sentora 2.0 Beta Ron-e 6 12 ,449 01-01-2022, 11:56 AM
Last Post: TGates
Can not access Sentora ThomasMoss 4 6 ,650 01-01-2022, 10:41 AM
Last Post: TGates

Forum Jump:


Users browsing this thread: 1 Guest(s)