Improper input validation: Difference between revisions

Content deleted Content added
mNo edit summary
Henke37 (talk | contribs)
m wording
Line 19:
=== String termination ===
In many environments, it is possible to truncate the string with clever input.
* PHP: '''%00''' (NUL) can terminate strings, when used for API calls that uses it to terminate strings.
* Oracle: '''CHR(0)''' (NUL) can terminate strings when used for e.g. EXECUTE IMMEDIATE.