GNOME Bugzilla – Bug 741777
libtracker-sparql: Document requirement to escape constructed queries
Last modified: 2014-12-22 18:58:57 UTC
Trivial patch attached, in response to some real-world code seen which contained injection vulnerabilities.
Created attachment 293068 [details] [review] libtracker-sparql: Document requirement to escape constructed queries Bring SQL injection to the front of people’s minds when using the APIs so that hopefully they don’t write injectable code.
Comment on attachment 293068 [details] [review] libtracker-sparql: Document requirement to escape constructed queries Looks good to me, thanks for the patch! Please commit :)
Attachment 293068 [details] pushed as 87a539e - libtracker-sparql: Document requirement to escape constructed queries