Current time: 05-25-2012, 12:38 AM Hello There, Guest! (LoginRegister)


[B] Apostrophes in usernames gave me an SQL error
04-07-2009, 11:09 AM (This post was last modified: 04-07-2009 11:10 AM by Fábio Maia.)
Post: #1
[B] Apostrophes in usernames gave me an SQL error
So, the thing is: I just invited a friend of mine to my forums, and he registered with the username Music'. He told me that after registration he got an error dealing with "username=Music'' (he didn't remeber anything else, since he didn't print it).
And when I was browsing my forums, when I click in any thread which my friend posted in, I got the same error as he did (and he confirmed it, when he got the error again).
Then, I searched for the error here: http://wiki.mybboard.net/index.php/Help:...r_Messages but I didn't find anything. I was going to ask for help already, but then I noticed the error and I think he can't register with an apostrophe in the username.
I changed his nickname (cut'd the apostrophe) and I can now browse every thread he posted in.

Here's the error:


Attached File(s) Thumbnail(s)
   
Find all posts by this user
04-07-2009, 11:11 AM
Post: #2
RE: Apostrophes in usernames gave me an SQL error
Hamin' X

MyBB escapes apostrophes in usernames, but a plugin may not, which may cause an error.

Download My Plugins
My Personal Site - Twitter
[Image: eX4bjF]
Visit this user's website Find all posts by this user
04-07-2009, 11:16 AM (This post was last modified: 04-07-2009 11:23 AM by Fábio Maia.)
Post: #3
RE: Apostrophes in usernames gave me an SQL error
hmm ok. I'll rename him to Music' again, and keep deactivating plugins till it works.
Yes, it was a plugin problem. I deactivated MyReputation (from MyBBSource) and it does work now.
Find all posts by this user
04-07-2009, 11:50 AM (This post was last modified: 04-07-2009 12:05 PM by Michael S..)
Post: #4
RE: Apostrophes in usernames gave me an SQL error
I'm marking this as bogus as it is the fault of a plugin. Please note that this issue is a security vulnerability. You should contact the author of the plugin so that he can publish an update.

Greets,
Michael
-------------
[Image: donation_drive_sig.png]
Visit this user's website Find all posts by this user


Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Contact Us | MyBB | Return to Top | Return to Content | Lite (Archive) Mode | RSS Syndication