hi everyone,
i’ve been reading about prepared statements and sql attacks, etc, and it turns out that even mysql_escape_string() isn’t enough in some cases (see:
http://ilia.ws/archives/103-mysql_real_escape_string-versus-Prepared-Statements.html) to filter submitted data, nor is mysql_real_escape_string. prepared statements are much better, but the old core doesn’t use them.
so, i was thinking, it’d be safer to compare md5 hashes of data with md5 hashes of submitted data, specifically in the web login processor.
I think the following is safer than without the md5 hashes (from weblogin.processor.inc.php lines 16-18):
$sql = "SELECT wu.*
FROM $dbase.`".$table_prefix."web_users` wu
WHERE MD5(wu.id)='".md5(mysql_escape_string($id))."'";
any thoughts? i’d submit this myself to svn, but still haven’t worked it out yet

(been very busy...)