SQL injection attack

Andrew McNamara <[email protected]> Wed, 24 May 2006 14:21:16 +1000
Newsgroups gmane.comp.python.db.pypgsql.user
Message-ID <[email protected]>
Should pyPgSQL attempt to mitigate this, or just count on Postgresql to
"fix" it?:

    http://www.postgresql.org/about/news.561
    http://www.newsforge.com/article.pl?sid=06/05/23/2141246

    >>> from pyPgSQL import PgSQL
    >>> PgSQL.PgQuoteString("\xbf\x27")
    "'\xbf\\''"

-- 
Andrew McNamara, Senior Developer, Object Craft
http://www.object-craft.com.au/


-------------------------------------------------------
All the advantages of Linux Managed Hosting--Without the Cost and Risk!
Fully trained technicians. The highest number of Red Hat certifications in
the hosting industry. Fanatical Support. Click to learn more
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=107521&bid=248729&dat=121642