Love Fuel?    Donate

FuelPHP Forums

Ask your question about FuelPHP in the appropriate forum, or help others by answering their questions.
Quote Identifier Security Advisory
  • Hi,

    With regards to the security advisory for the quote_identifer method of the DB connections, patched here: https://github.com/fuel/core/commit/270ba79b39e93317e88260a162872ea48e8cfb2c

    Is this only necessary if running PHP 5.5 [or higher] as it looks like the patch was needed following the depreciation of the /e modifier of preg_replace?

    I'm still running FuelPHP 1.5 on PHP 5.4 and upgrading to 1.7 isn't straight forward right now.

    Thanks
  • It is in some cases possible that malicious code is injected to the the fact that the $1 will be replaced as-is with the input value. If that is posted and/or insuficciently validated, you run a risk.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

In this Discussion