• Resolved MrBrian

    (@mrbrian)


    An author was trying to publish a story and didn’t know why he was being blocked – he copy pasted some HTML into the post i’m guessing. All because there’s a | in an ID variable?

    Firewall log:
    02/Mar/16 16:58:02 #7705376 high 257 174.88.43.1 POST /wp-admin/post.php - SQL injection (comparison operator #2)

    Code in post triggering firewall:

    <img id="252785_mceSrc|https://thenypost.files.wordpress.com/2015/12/bern.jpg?quality=100&strip=all&w=664&h=441&crop=1" class="" src="https://thenypost.files.wordpress.com/2015/12/bern.jpg?quality=100&strip=all&w=664&h=441&crop=1" alt="" width="598" height="397" />

    https://wordpress.org/plugins/ninjafirewall/

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘False positive: comparison operator in post content’ is closed to new replies.