-
Type:
Enhancement
-
Status: Closed
-
Priority:
Medium
-
Resolution: Done
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: BenAdmin
-
Labels:None
-
Module:BenAdmin - Security
-
Reported by:Support
-
Item State:Production Complete - Closed
We need to verify OR condition for SQL injection. Scenario which was tried to save is as mentioned below-
asdf' OR '1'='1
We have verified OR with single quote and at least one space before and after OR.
Field | Original Value | New Value |
---|---|---|
Assignee | Vijay Siddha [ vijays ] | Deepali Tidke [ deepalit ] |
Status | New Request [ 10029 ] | Pending for Approval [ 10002 ] |
Status | Pending for Approval [ 10002 ] | Approved for Development [ 10003 ] |
Status | Approved for Development [ 10003 ] | In Development [ 10007 ] |
Item State | Parent values: LB QA(10201) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Attachment | WT-3873.doc [ 24007 ] |
Attachment |
|
Attachment | WT-3873.doc [ 24507 ] |
Assignee | Deepali Tidke [ deepalit ] | Prasad Pise [ prasadp ] |
Attachment | image006.png [ 24732 ] |
Attachment |
|
Attachment | WT-3873.doc [ 25623 ] |
Assignee | Prasad Pise [ prasadp ] | Vijayendra Shinde [ ID10506 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: LB QA(10201)Level 1 values: Re-open(10212) |
Item State | Parent values: LB QA(10201)Level 1 values: Re-open(10212) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) |
Assignee | Vijayendra Shinde [ ID10506 ] | Prasad Pise [ prasadp ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Pending for Stage Approval [ 10300 ] |
Status | Pending for Stage Approval [ 10300 ] | Approved for Stage [ 10030 ] |
Status | Approved for Stage [ 10030 ] | Stage Testing [ 10201 ] |
Status | Stage Testing [ 10201 ] | Pending for Production Approval [ 10301 ] |
Status | Pending for Production Approval [ 10301 ] | Approved for production [ 10034 ] |
Status | Approved for production [ 10034 ] | Production Testing [ 10202 ] |
Resolution | Fixed [ 1 ] | |
Status | Production Testing [ 10202 ] | Production Complete [ 10028 ] |
Item State | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) | Parent values: Production Complete(10222)Level 1 values: Closed(10223) |
Status | Production Complete [ 10028 ] | Closed [ 6 ] |
Transition | Time In Source Status | Execution Times |
---|
|
26m 52s | 1 |
|
2s | 1 |
|
7s | 1 |
|
32d 17h 27m | 2 |
|
20d 1h 24m | 2 |
|
2d 2h 19m | 3 |
|
3s | 1 |
|
3s | 1 |
|
3s | 1 |
|
4s | 1 |
|
4s | 1 |
|
7s | 1 |
|
49d 1h 24m | 1 |
|
90d 4h 58m | 1 |
Affected Files:
/branches/LB/Config Files WT Stage/Web Server/Web.config
/branches/LB/Web/SharedFunctionWebTier/SharedFunctionWebTier/Modules/CustomModelBinder.cs