Fix SQL injections in ajax_table.php (#11920)

* Fix SQL injections via searchPhrase parameter

* Fix SQL injections via address parameter

* Fix sort injection

Co-authored-by: Tony Murray <murraytony@gmail.com>
This commit is contained in:
Jellyfrog
2020-07-10 16:17:09 +02:00
committed by GitHub
parent 290398bd9b
commit 32f72bc1ab
20 changed files with 90 additions and 25 deletions

View File

@@ -28,7 +28,9 @@ if (!Auth::user()->hasGlobalRead()) {
$sql .= " WHERE $where";
if (isset($searchPhrase) && !empty($searchPhrase)) {
$sql .= " AND (`hostname` LIKE '%$searchPhrase%' OR `processor_descr` LIKE '%$searchPhrase%')";
$sql .= " AND (`hostname` LIKE ? OR `processor_descr` LIKE ?)";
$param[] = "%$searchPhrase%";
$param[] = "%$searchPhrase%";
}
$count_sql = "SELECT COUNT(`processor_id`) $sql";