<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									SQL Injection vulnerability in eFiction - eFiction Software News				            </title>
            <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/</link>
            <description>Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Mon, 20 Apr 2026 19:36:40 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-21057</link>
                        <pubDate>Wed, 09 Jun 2021 10:18:48 +0000</pubDate>
                        <description><![CDATA[nice pice of history]]></description>
                        <content:encoded><![CDATA[<p>nice pice of history</p>]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>cristodulo</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-21057</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20099</link>
                        <pubDate>Sun, 25 Jan 2015 09:39:09 +0000</pubDate>
                        <description><![CDATA[Changes haven been included in the latest release, 3.5.5Topic locked.]]></description>
                        <content:encoded><![CDATA[Changes haven been included in the latest release, 3.5.5<br>Topic locked.]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>Sheepcontrol</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20099</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20046</link>
                        <pubDate>Sat, 15 Nov 2014 21:32:23 +0000</pubDate>
                        <description><![CDATA[I am very willing too to help with beta testing, anything you need]]></description>
                        <content:encoded><![CDATA[I am very willing too to help with beta testing, anything you need]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>jacci</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20046</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20045</link>
                        <pubDate>Sat, 15 Nov 2014 12:27:29 +0000</pubDate>
                        <description><![CDATA[It seems to be.&nbsp; Once I backed out the config.php changes, all of the weird extra characters disappeared when I did the hand-edits to the HTML input editor.-- jb]]></description>
                        <content:encoded><![CDATA[It seems to be.&nbsp; Once I backed out the config.php changes, all of the weird extra characters disappeared when I did the hand-edits to the HTML input editor.<br><br>-- jb]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>jetblack</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20045</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20044</link>
                        <pubDate>Sat, 15 Nov 2014 09:17:05 +0000</pubDate>
                        <description><![CDATA[Can I get a post of Step 3 so I can back out the changes?-- JbEDIT: Nevermind.&nbsp; I found it and edited it out.So it&#039;d good now?]]></description>
                        <content:encoded><![CDATA[<blockquote><br>Can I get a post of Step 3 so I can back out the changes?<br><br>-- Jb<br><br>EDIT: Nevermind.&nbsp; I found it and edited it out.<br></blockquote><br><br>So it&#039;d good now?]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>Sheepcontrol</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20044</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20043</link>
                        <pubDate>Sat, 15 Nov 2014 05:11:54 +0000</pubDate>
                        <description><![CDATA[Darn, that&#039;s what I was fearing. Well, as I said, I don&#039;t know the code very well, ok, scratch that as well - I need to finish v5 ASAP :(Hey I&#039;m ready to beta test v5 whenever...]]></description>
                        <content:encoded><![CDATA[<blockquote><br><blockquote><br><br>Darn, that&#039;s what I was fearing. Well, as I said, I don&#039;t know the code very well, ok, scratch that as well - I need to finish v5 ASAP :(<br></blockquote><br><br>Hey I&#039;m ready to beta test v5 whenever you are ready.&nbsp; :agree:<br></blockquote><br><br>I&#039;d also be up for doing any beta testing when you are ready.&nbsp;]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>HPFanFicArchive.Com</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20043</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20042</link>
                        <pubDate>Fri, 14 Nov 2014 22:52:53 +0000</pubDate>
                        <description><![CDATA[Can I get a post of Step 3 so I can back out the changes?-- JbEDIT: Nevermind.&nbsp; I found it and edited it out.]]></description>
                        <content:encoded><![CDATA[Can I get a post of Step 3 so I can back out the changes?<br><br>-- Jb<br><br>EDIT: Nevermind.&nbsp; I found it and edited it out.]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>jetblack</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20042</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20041</link>
                        <pubDate>Fri, 14 Nov 2014 22:51:09 +0000</pubDate>
                        <description><![CDATA[I&#039;m getting a bunch of reports from authors stating that &quot;rn&quot; is being added to each line since I applied the hotfix.&nbsp; Here&#039;s an examplematter what I do on the HTML ...]]></description>
                        <content:encoded><![CDATA[I&#039;m getting a bunch of reports from authors stating that &quot;rn&quot; is being added to each line since I applied the hotfix.&nbsp; Here&#039;s an example:<br><br>http://www.adastrafanfic.com/viewstory.php?sid=2061&amp;chapter=37<br><br>No matter what I do on the HTML editor side, I cannot remove those characters.&nbsp; They persist over and over. <br><br>-- jb]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>jetblack</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20041</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20040</link>
                        <pubDate>Fri, 14 Nov 2014 20:13:27 +0000</pubDate>
                        <description><![CDATA[Darn, that&#039;s what I was fearing. Well, as I said, I don&#039;t know the code very well, ok, scratch that as well - I need to finish v5 ASAP :(Hey I&#039;m ready to beta test v5 whenever...]]></description>
                        <content:encoded><![CDATA[<blockquote><br><br>Darn, that&#039;s what I was fearing. Well, as I said, I don&#039;t know the code very well, ok, scratch that as well - I need to finish v5 ASAP :(<br></blockquote><br><br>Hey I&#039;m ready to beta test v5 whenever you are ready.&nbsp; :agree:]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>babaca</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20040</guid>
                    </item>
				                    <item>
                        <title>Re: SQL Injection vulnerability in eFiction</title>
                        <link>https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20039</link>
                        <pubDate>Fri, 14 Nov 2014 20:08:38 +0000</pubDate>
                        <description><![CDATA[Thank you, Robert for pointing this out, and thank you, Sheepcontrol for working on the fix. I wanted to point out that the 2 lines of code that were previously added to the config.php file,...]]></description>
                        <content:encoded><![CDATA[<blockquote><br>Thank you, Robert for pointing this out, and thank you, Sheepcontrol for working on the fix. <br><br>I wanted to point out that the 2 lines of code that were previously added to the config.php file, and now are listed for the dbfuctions.php file:<br><pre>$_GET = array_map(&#039;stripslashes&#039;, $_GET);<br>$_POST = array_map(&#039;stripslashes&#039;, $_POST);</pre><br>May help with the SQL injection issue, but they throw off some of the site functionality. A member of my site emailed me to let me know that when she was trying to add a challenge, the site wouldn&#039;t save the characters she was trying to tie to the challenge. I checked, and she was correct. It looks like any input that comes from a box where multiple options can be chosen is being disregarded (for ex. in the advanced search it won&#039;t use selected classtypes to include/exclude).<br></blockquote><br><br>Darn, that&#039;s what I was fearing. Well, as I said, I don&#039;t know the code very well, ok, scratch that as well - I need to finish v5 ASAP :(]]></content:encoded>
						                            <category domain="https://efiction.org/community/efiction-software-news/">eFiction Software News</category>                        <dc:creator>Sheepcontrol</dc:creator>
                        <guid isPermaLink="true">https://efiction.org/community/efiction-software-news/sql-injection-vulnerability-in-efiction/paged/2/#post-20039</guid>
                    </item>
							        </channel>
        </rss>
		