We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26474
    • 3 Posts
    In the function doSearch in file AjaxSearch.inc.php there should be some sort of sanitizing of DB variable.

    so I added
    $searchString = mysql_escape_string($searchString);

    Why was something this simple missed?

      • 14050
      • 788 Posts
      I am not 100% certain, but I am not sure why the search string would ever be placed in the the database, so there should be no need to escape it in the first place.
        Jesse R.
        Consider trying something new and extraordinary.
        Illinois Wine

        Have you considered donating to MODx lately?
        Donate now. Every contribution helps.
        • 22815
        • 1,097 Posts
        It is used in a query, which therefore means that the search string is in code that is executed on the database in some form... whether that could actually be used maliciously I’m not sure. But sanitising input is not only required where the string would be stored. Any string that is being used to build up an SQL query should be cleaned to avoid the possibility of someone wrapping the query up, putting their own malicious query in and then starting up another query.
          No, I don't know what OpenGeek's saying half the time either.
          MODx Documentation: The Wiki | My Wiki contributions | Main MODx Documentation
          Forum: Where to post threads about add-ons | Forum Rules
          Like MODx? donate (and/or share your resources)
          Like me? See my Amazon wishlist
          MODx "Most Promising CMS" - so appropriate!
          • 26474
          • 3 Posts
          i played with it a little bit and couldnt inject my own code, but im sure with enough time i could figure it out. I think that it kept throwing errors even w/ injected code b/c i couldnt get SQL comments to work (is it possible to have mysql comments disabled?)