4 ms·
In the verifier.php I see a problem here: $uid=$_COOKIE['uid']; $uname=$_COOKIE['uname']; $sql="SELECT * FROM users WHERE username='$uname'"; The
by infinity 15y ago
In the verifier.php I see a problem here:
$uid=$_COOKIE['uid'];
$uname=$_COOKIE['uname'];
$sql="SELECT * FROM users WHERE username='$uname'";
The $uname is set from the value of 'uname' in the $_COOKIE array, but I see no input validation here.
If I were an evil attacker, I could send arbitrary cookie data to the server, it would end up in the $_COOKIE superglobal. If I include some SQL code, ... All input is evil!
Later, in the welcome.php the $_COOKIE['uname'] is echoed without any escapes.
- maratd 15y ago> I see a problem here: No, that's not a problem. It's a disaster. Whoever wrote that should be shot. If you're going to stick things from a cookie into your database, at least have enough brains to use a prepared statement.