3 ms·
> Because in an alternative universe, they could have chosen to treat log messages like SQL where parameters are passed separately. They did chose to do this.
by zenexer 5y ago
> Because in an alternative universe, they could have chosen to treat log messages like SQL where parameters are passed separately.
They did chose to do this. The vulnerability arises even when this is done correctly.
Pseudocode:
log("example: %s", userInput)
This is still vulnerable. The parsing that exposes the vulnerability occurs on both the format string and userInput here.