File tree Expand file tree Collapse file tree 2 files changed +11
-3
lines changed
php/lang/security/injection Expand file tree Collapse file tree 2 files changed +11
-3
lines changed Original file line number Diff line number Diff line change @@ -31,6 +31,14 @@ function test4() {
31
31
return $ info ;
32
32
}
33
33
34
+ function test5 () {
35
+ // ruleid: tainted-sql-string
36
+ $ query = "
37
+ SELECT * FROM table WHERE Id = ' " .$ _GET ['url ' ]."' " ;
38
+ $ info = mysql_query ($ query );
39
+ return $ info ;
40
+ }
41
+
34
42
// True Negatives
35
43
36
44
function test1 () {
Original file line number Diff line number Diff line change @@ -46,16 +46,16 @@ rules:
46
46
sprintf($SQLSTR, ...)
47
47
- metavariable-regex :
48
48
metavariable : $SQLSTR
49
- regex : .*\b(?i) (select|delete|insert|create|update|alter|drop)\b.*
49
+ regex : (?is) .*\b(select|delete|insert|create|update|alter|drop)\b.*
50
50
- patterns :
51
51
- pattern : |
52
52
"...$EXPR..."
53
53
- metavariable-regex :
54
54
metavariable : $EXPR
55
- regex : .*\b(?i) (select|delete|insert|create|update|alter|drop)\b.*
55
+ regex : (?is) .*\b(select|delete|insert|create|update|alter|drop)\b.*
56
56
- patterns :
57
57
- pattern : |
58
58
"$SQLSTR".$EXPR
59
59
- metavariable-regex :
60
60
metavariable : $SQLSTR
61
- regex : .*\b(?i) (select|delete|insert|create|update|alter|drop)\b.*
61
+ regex : (?is) .*\b(select|delete|insert|create|update|alter|drop)\b.*
You can’t perform that action at this time.
0 commit comments