aboutsummaryrefslogtreecommitdiff
path: root/GradeBook_lib.tcl
diff options
context:
space:
mode:
authorEugeniy Mikhailov <evgmik@gmail.com>2012-12-18 10:51:46 -0500
committerEugeniy Mikhailov <evgmik@gmail.com>2012-12-18 10:51:46 -0500
commitd1191c062e2c14b44c5bfe16dbd593ce6d400700 (patch)
treedab519269cecaf241d542735a4a7d3b0946b517c /GradeBook_lib.tcl
parent38aa8e28b85a716c45dc23c7039067069ff75a5d (diff)
downloadGradeBook-d1191c062e2c14b44c5bfe16dbd593ce6d400700.tar.gz
GradeBook-d1191c062e2c14b44c5bfe16dbd593ce6d400700.zip
screen potential sql injection in Authenticate_User proc
Diffstat (limited to 'GradeBook_lib.tcl')
-rwxr-xr-xGradeBook_lib.tcl2
1 files changed, 1 insertions, 1 deletions
diff --git a/GradeBook_lib.tcl b/GradeBook_lib.tcl
index 4876c82..f379533 100755
--- a/GradeBook_lib.tcl
+++ b/GradeBook_lib.tcl
@@ -1868,7 +1868,7 @@ proc Authenticate_User { user_requested password } {
return __non_existing_user__
}
- set eval_str [list SELECT UserName FROM PasswordsTable WHERE UserName='$user_requested' AND PasswordHash='$PasswordHash']
+ set eval_str [list SELECT UserName FROM PasswordsTable WHERE UserName=:user_requested AND PasswordHash=:PasswordHash]
set err [catch {
pdb eval $eval_str valid_user_name_array {}
} errStat ]