Details
-
Bug
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Fixed
-
3.2.8
-
None
Description
Binary parameters in case of client-side prepare(default EDSERVER=0 for SQLExecDirect or PREPONCLIENT=1 for SQLPrepare + SQLExecute) are affected.
This can lead to SQL injection.
Problematic charsets big5, gbk, sjis, cp932
Attachments
Issue Links
- relates to
-
CONCPP-153 Query parameters escaping does not consider if parameter data is encoded in multibyte charset
-
- Closed
-