SQL Syntax Error - BxWallDb.php

The error occured when an apostrophe (') was used in the description when adding an image to the wall.  Is there a way to get around this so a user can add normal punctuation to their image descriptions?

The user entered:

LifeCycle's products bla bla...

 

1.  It doesn't give an error to the user.  It just doesn't submit and post their image to the wall.

2.  They try submitting the image several times creating the same database error over and over.

Quote · 27 Aug 2010

this seems fixed BUT is the value now only checked clientside via JS? caus a apostrophe causing a mysql error shown in browser is ALWAYS a bad sign ... it means you can probably do SQL injects ... doesnt php autoescape those chars for the last 5 years? how can this be broken?

Quote · 2 Sep 2010

What do you mean it seems to be fixed?

I'm running 7.02 and anytime an apostrophe is placed in the description while adding a photo/image to the wall creates a database error.  The member doesn't receive notice of an error so they keep trying to add their image creating several database errors.

Add an image to a wall using an apostrophe (in the description) and see if you get an error.

Quote · 2 Sep 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.