HTTP Verb Tampering
Common HTTP Methods:
Types of Insecure Configurations:
<Limit GET POST> Require valid-user </Limit>
$pattern = "/^[A-Za-z\s]+$/"; if(preg_match($pattern, $_GET["code"])) { $query = "Select * from ports where port_code like '%" . $_REQUEST["code"] . "%'"; ...SNIP... }
Last updated