diff options
author | Derek Jones <derek.jones@ellislab.com> | 2011-04-19 23:13:48 +0200 |
---|---|---|
committer | Derek Jones <derek.jones@ellislab.com> | 2011-04-19 23:13:48 +0200 |
commit | 6ae70cc8499499b5d77d77ec8974f95873edb861 (patch) | |
tree | 85b39e2ae9018e77f6fe8647b1004f91764001ce /application | |
parent | 9ce4385cfc976e309ee12c53726abfd4f066ac3f (diff) |
modified MySQL and MySQLi drivers to address a potential SQL injection attack vector when multi-byte character set connections are employed. (Does not impact Latin-1, UTF-8, etc. encodings)
Diffstat (limited to 'application')
-rw-r--r-- | application/config/database.php | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/application/config/database.php b/application/config/database.php index 24d611ac5..fa541a734 100644 --- a/application/config/database.php +++ b/application/config/database.php @@ -26,6 +26,12 @@ | ['cachedir'] The path to the folder where cache files should be stored | ['char_set'] The character set used in communicating with the database | ['dbcollat'] The character collation used in communicating with the database +| NOTE: For MySQL and MySQLi databases, this setting is only used +| as a backup if your server is running PHP < 5.2.3 or MySQL < 5.0.7. +| There is an incompatibility in PHP with mysql_real_escape_string() which +| can make your site vulnerable to SQL injection if you are using a +| multi-byte character set and are running versions lower than these. +| Sites using Latin-1 or UTF-8 database character set and collation are unaffected. | ['swap_pre'] A default table prefix that should be swapped with the dbprefix | ['autoinit'] Whether or not to automatically initialize the database. | ['stricton'] TRUE/FALSE - forces 'Strict Mode' connections |