lederhosen: (Default)
[personal profile] lederhosen
Via RISKS:

The Oklahoma Department of Corrections published a web interface where the URL contained the SQL query executed to retrieve the data to be reported. Thus, any knowledgeable user could execute general SQL queries against a database containing large amounts of personal information -- including UPDATE statements (!) It was taken down only after management was shown that THEIR personal information was available.

Date: 2008-04-23 01:12 pm (UTC)
From: [identity profile] lederhosen.livejournal.com
DROP TABLE would work pretty well, too...

Profile

lederhosen: (Default)
lederhosen

July 2017

S M T W T F S
      1
2345678
9101112131415
16171819202122
2324252627 2829
3031     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 10th, 2025 04:55 pm
Powered by Dreamwidth Studios