SQL injection risk?

From: Steve Kass (skass@drew.edu)
Date: 07/23/02


Date: Mon, 22 Jul 2002 20:17:30 -0400
From: Steve Kass <skass@drew.edu>


This looks bad to me. Any thoughts?

Run the command below _at your own risk_ for a valid publication, then look in
c:\. Replication isn't my thing, so clear up any confusion on my part, but this
doesn't look good to me. Since sp_copysnapshot is available to public role
users, doesn't this let anyone do serious damage? I could as easily have done
... (del *.*) ...

SK