Database Security Products (MOSC)

MOSC Banner

Question about # single-line comments for SQL injection attacks

edited Aug 11, 2010 3:42AM in Database Security Products (MOSC) 2 commentsAnswered
We are looking at possibly opening up our cross-site scripting filter so that it allows the # character because this limitation is causing problems for many agencies.  We originally prevented the users from using the # character in any web request to the Commerce server because it can possibly be used for single-line comments for SQL injection attacks.  But after further examination, it appears that this # character for single-line comments was only supported in Oracle 8 and older versions.  Can you please confirm with Oracle whether or not they support the # character for comments in Oracle RDBMS 9.x and RDBMS 10.x ? 

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center