We have similar questions concerning the securitiy of formit-forms and would be very glad if anybody could help us to clarify the following
point:
We found that in formit-forms the following user-input is stored without any escaping in our database:
input --> stored
=================
\x00 --> \x00
\n --> \n
\r --> \r
\ --> \
\x1a --> \x1a
Seems that there is no escaping and we are worried if this could be a risk for mysql-injections?
Should formit2db therefore be updated with something like "mysql_real_escape_string"?
\n, \r and \ should probably be left alone. AFAIK, none of these char codes can do any harm in the database.
\x00 is the NULL hexadecimal code. Again, not really harmful, but some devs prefer to strip out any null characters before use.
\x0a is the newline hex code and should be left alone.