« Previous | Next»

php based home inventory system

Posted by coldtobi | 19 Apr, 2009, 21:07

I'm currently looking for a system for keeping an overview over my electronic parts I have "on stock", storing the datasheets and keeping and especially where I put them.

During this I found "home-inventory". Looks ok, but also lacks some features, like it can only store images...

PS: I have to rethink about the "looks ok". The first peek on the source code reveals, that the author did not care about sanitizing user input:

                // delete first picture if exist
                $sSql = 'SELECT ITM_Picture FROM Item WHERE ITM_ID = ' . $_REQUEST['id'];
                $pictName = fetchFromDb($sSql, true);

Aarrghh.

 

Anzeige



<—&mdash Showing ERROR? Click here!


Blog and Website | Comments (0) | Trackbacks (0)

Related Articles:

0 Comments | "php based home inventory system" »

Add comment

 

 This is the ReCaptcha Plugin for Lifetype

Due to German legislation, all comments are moderated. If you get NO error message, your comment is accepted by the system and will be released at the earliest opportunity. Sorry for the inconvenience this might cause.

Inappropiate comments might be edited or not accepted.