SQL injection risk?
From: Steve Kass (skass@drew.edu)
Date: 07/23/02
- Next message: Peter Lin: "Re: Transaction Log ??"
- Previous message: Anith Sen: "Re: sql server versions"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 22 Jul 2002 20:17:30 -0400 From: Steve Kass <skass@drew.edu>
This looks bad to me. Any thoughts?
Run the command below _at your own risk_ for a valid publication, then look in
c:\. Replication isn't my thing, so clear up any confusion on my part, but this
doesn't look good to me. Since sp_copysnapshot is available to public role
users, doesn't this let anyone do serious damage? I could as easily have done
... (del *.*) ...
SK
- Next message: Peter Lin: "Re: Transaction Log ??"
- Previous message: Anith Sen: "Re: sql server versions"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]