We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 12556
    • 103 Posts
    I’m sure that this isn’t what it seems like to me because I’m sure something this obvious didn’t get overlooked by everyone but the AjaxSearch snippet seems like it will allow users to inject SQL. I was testing it out and searched for something with a single quote and it came back and gave me this error:


    « Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ’%’ OR sc.longtitle LIKE ’%bloggin\\’%’ OR sc.description LIKE ’%bloggin\\’%’ OR ’ at line 1 »

    ...which made me think that I had altered the query itself, i.e. it wasn’t sanitized and therefore could be vulnerable to an injection attack. Again I’m sure it’s NOT what it looks like to me because people a lot more knowledgeable than I would surely have picked up on it by now but at the very least the AjaxSearch snippet is broken. Users should be able to search for things with single quotes in them.
    Dave

      • 12556
      • 103 Posts
      Thanks for moving my post. I wasn’t sure where it should go.
        • 5811
        • 1,717 Posts
        Do you use the last release of AjaxSearch : 1.8.1 ?

        Could you give me your search term (as I understand : bloggin’ ) ?

        Could you try to reproduce this issue on the AS demo site :http://www.modx.wangba.fr/index.php?id=190 Use the upper menu to select one of demo.

        Thks.
          • 12556
          • 103 Posts
          I was able to reproduce it on the demo site with version 1.7.1 but not 1.8.0 or 1.8.1. I just recently did a clean install of MODx 0.9.6.2 and I am using the version of AjaxSearch that was included with that, which must be 1.7.1 but I haven’t checked yet.