Get your own customer support community
 

Sql injection possibility

When adding a hobby, the "type of leisure" does not seem to escape the apostrophe character. Indeed, if we entered a kind of entertainment such as "Centres d'intérêts" bugg validation and field is not changed. In addition, this could be a flaw to hack your website because if that is what I think it would be possible to include a sql injection in.

I use the French version of DoYouBuzz and I'm French so sorry for my bad english.

You can see the bugg details here:
 
indifferent I’m scared for you
Inappropriate?
1 person has this problem

User_default_medium