Ticket #384 (closed バグ指摘: 修正済)

Opened 14 years ago

Last modified 14 years ago

マイページのほかのお届け先編集画面でのSQLインジェクションの危険性

Reported by: takegami Owned by: somebody
Priority: Milestone: EC-CUBE2.3.1
Component: フロント Version: 2.3.0RC-1
Keywords: Cc:
修正済み:

Description

1系 data/mypage/delivery_addr.php 2系 data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php

で他人の住所を上書きできる危険性

Change History

comment:1 Changed 14 years ago by takegami

  • Status changed from new to closed
  • Resolution set to 修正済

r17679 で修正

Note: See TracTickets for help on using tickets.