logoalt Hacker News

voxic11today at 5:11 PM1 replyview on HN

Keep in mind this project is a 25 year old PHP application.


Replies

zarzavattoday at 5:27 PM

That actually makes it more confusing since a 25 year old PHP application is exactly where you'd expect to find SQL injection vulnerabilities.

If I were in charge of a 25 year old PHP application, tracking down every SQL query and converting it to a safe form would high on my list of priorities. You don't need AI for that, just ripgrep and a basic amount of care for your users.

show 2 replies