there are no words
Apr. 15th, 2008 12:03 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
Oklahoma sex offender registry exposes and executes SQL statements in the URL, enabling downloads of social security numbers, birthdates, addresses, et cetera. Who knows, maybe their site executed INSERT statements too.
Nobody accessing sensitive government databases should assume that users don't know SQL. And yet.
Nobody accessing sensitive government databases should assume that users don't know SQL. And yet.