View Single Post
psychonic

BAFFLED
Join Date: May 2008
Old 11-03-2013 , 16:57   Re: Last Users Connected
Reply With Quote #149

Quote:
Originally Posted by Mirandor View Post
Thanks for sharing it, but how can we be sure that this release has no potential sql injection?
The archive with "src" in the name is the source code. A cursory look suggests that there is no injection vector as the only strings inserted are added in with sqlite3_snprintf with the %q format specifier, which properly quotes them.
psychonic is offline