Problem with SQL Security Settings

I've run into an odd problem since moving to ColdFusion 8
Enterprise Edition. Any text string submitted to an action page
through a form will return an error ("Executing the SQL statement
is not allowed.") if it contains text that conforms to a disallowed
SQL command. For example, I've turned off the "create" as an
allowed SQL statement in my datasources. If I submit a form that
includes the following text, "Go back to the beginning of the
document; create a title," I get the error message. This occurs in
richtext form fields as well as in standard input form fields. If I
turn off the security setting so that "create" is an allowed SQL
command, the error goes away and (fortunately) no table is created.
It appears that ColdFusion is checking for the presence of
illegal commands even in text strings that are delimited by single
quotes in a query -- and even when those text strings wouldn't
actually do anything to a database.
Has anyone else run into this? Am I missing a setting on my
Administrator? Or am I missing something obvious? I'm not pleased
about the options I have at this point -- turning off some of my
security settings or allowing errors to occur and telling people
not to use semicolons as a workaround.
Thanks for any help you might offer.
Mike

Mike Palmquist wrote:
> Thanks for any help you might offer.
>
> Mike
>
Are you using <cfqueryparam...> tags? It sounds like
you are directly
passing the form text into the SQL statement. If this is what
you are
doing, then you are probably getting the expected, safest
results. If
you do not use the <cfqueryparam...> tag to tell
ColdFusion and your
database that this is a bound parameter then it is possible
that the
text is expected to contain SQL code and it will be parsed as
such.
To give clearer advice it would be helpful to see an example
of your code.

Similar Messages

  • SQL Security Settings - New DB Build Standards at my company

    Re: SQL Security Settings - New DB Build Standards at my company

    How would you interpret the two new db build standards below?
    1) Execute permissions on stored procedures revoked
    2) Access and/or Permissions: Command shell permissions revoked
    Hi TheBrenda,
    Agree with Dan.
    Firstly, according to this article:
    Managing Permissions with Stored Procedures in SQL Server, one method to protect your database is to implement all data access using stored procedures or user-defined functions. You revoke or deny all permissions to underlying objects, such as tables, and
    grant EXECUTE permissions on stored procedures. This effectively creates a security perimeter around your data and database objects.
    Secondly, access to
    xp_cmdshell should be restricted to highly privileged users. As Dan’s post, by default sysadmin fixed-role users have access to the xp_cmdshell procedure. Users that don’t belong to sysamin fixed role must be impersonated with a xp_cmdshell Proxy Account.
    Regards,
    Lydia Zhang

  • Gmail error message "We've detected a problem with your cookie settings." Tried everything...

    THIS IS THE PAGE:
    Google
    We've detected a problem with your cookie settings.
    Enable cookies
    Make sure your cookies are enabled. To enable cookies, follow these browser-specific instructions.
    Clear cache and cookies
    If you have cookies enabled but are still having trouble, clear your browser's cache and cookies.
    Adjust your privacy settings
    If clearing your cache and cookies doesn't resolve the problem, try adjusting your browser's privacy settings. If your settings are on high, manually add www.google.com to your list of allowed sites. Learn more
    ©2013 Google - Google Home - Terms of Service - Privacy Policy - Help
    i have done everything listed here so many times and nothing is fixing this. Made sure cookies were enabled, cleared cache and cookies, made sure Gmail was approved in security settings, and then as a last ditch effort, I disabled all add-ons for Firefox and still no Gmail... I was so desperate that I even re-installed ff-19 and still cannot get into my email account. What is going on here? Any help or small nudge in the correct direction would be much appreciated!

    I used the same thing used in the first link 950400...
    Firefox > Options > Options > Privacy > remove individual cookies > typed google > remove all cookies > typed gmail > remove all cookies
    restarted Firefox and now I can log into gmail...

  • I have problem with the security question which i forgot the answer how can i change it as i already have apple id and password

    I have problem with the security question which i forgot the answer how can i change it as i already have apple id and password

    You may reset the password on your account by opening https://iforgot.apple.com/ in Safari and entering your Apple ID (your email address, which the moderators should have removed earlier).
    You won't be able to set the password to your email address, or a recently-used password (if I remember correctly).
    Once you change your password, you should update your password on your iOS device in Settings > iTunes & App Store, then tapping the "Apple ID: <username>" cell at the top to re-enter your password.  (Your iOS device may prompt you for the new password before getting to Settings as well.)
    Hope that helps.  If you have a different issue, please post a follow-up message.

  • I am having some huge problems with my colorspace settings. Every time I upload my raw files from my Canon 5D mark II or 6D the pics are perfect in color. That includes the back of my camera, the pic viewer on my macbook pro, and previews. They even look

    I am having some huge problems with my colorspace settings. Every time I upload my raw files from my Canon 5D mark II or 6D the pics are perfect in color. That includes the back of my camera, the pic viewer on my macbook pro, and previews. They even look normal when I first open them in photoshop. I will edit, save, and then realize once i've sent it to myself to test the color is WAY off. This only happens in photoshop. I've read some forums and have tried different things, but it seems to be making it worse. PLEASE HELP! Even viewing the saved image on the mac's pic viewer is way off once i've edited in photoshop. I am having to adjust all my colors by emailing myself to test. Its just getting ridiculous.

    Check the color space in camera raw, the options are in the link at the bottom of the dialog box. Then when saving make sure you save it to the srgb color space when sending to others. Not all programs understand color space and or will default to srgb. That won't necessarily mean it will be accurate, but it will put it in the ballpark. Using save for web will use the srgb color space.

  • There is a problem with the security certificate of the proxy server. Error code 18 and 38.

    Hi All,
    After several hours and a short night of sleep I'm out of ideas and hopefully someone here can help me trying to solve this one. First of all the situation:
    Exchange 2013 on a remote location with a CA-certificate.
    Outlook 2010 and 2013 on different locations, locally installed and on RDS.
    When I open Outlook on my laptop all is fine, no errors, good sync, no problem. But when I open Outlook on our Remote Desktop Servers with Outlook 2013 I'm getting errors like "There is a problem with the security certificate of the proxy server. The
    name on the security certificate is invalid or does not match the name of the site. Outlook is unable to connect to this server. (Error code 18)". Opening Outlook 2010 the message is the same, but the error code now is 38.
    After this Outlook opens and is working, there's one more error though. After a while an security warning pops up with the message: "Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the
    site's security certificate. * The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority. * The security certificate is valid. * The name on the security
    certificate is invalid or does not match the name of the site."
    Strangest thing is, it is the certificate of my RDS! It isn't my valid en officially bought certificate from my mailserver. What's going on? I'm out of options, what I've tried so far (in random order):
    - restarting mailserver and AD;
    - restarting switches;
    - restarting routers;
    - restarting RDS, AD and all other servers;
    - bypassed proxyserver for RDS;
    - created a new profile;
    - checked recently installed updates;
    - checked certificate on mailserver;
    - checked RDS on a different location, working fine.
    Nothing helped, what can I do next? Please advice.
    Regards.

    Found a thread that solves half my problem (https://social.technet.microsoft.com/Forums/office/en-US/70d18244-889a-4d95-ac3f-e234672a82b2/there-is-a-problem-with-the-proxy-servers-security-certificate-error-when-starting-outlook?forum=exchangesvrclients).
    The first message can be suppressed by adding this to the Exchange config:
    set-outlookprovider -Identity EXCH -CertprincipalName msstd:webmail.domain.tld
    set-outlookprovider -Identity EXPR -CertprincipalName msstd:webmail.domain.tld
    Giving the command get-outlookprovider, gives me empty information regarding the certprinipalname. Filled
    this and after recreating the profile or deleting the ost-file I still have the second alert with the local certificate of my RDS.
    Not completely where I want to be, any help regarding the second alert is greatly appreciated!

  • A Problem with Region Format Settings

    Hi!
    I have a peculiar problem with Region Format settings on my iPod touch (Settings > General > International > Region Format). It appears that iPod touch can support more region formats than it is stated on that list. Once I registered my iPod, I selected my location, Lithuania, and it automatically set (I think because of this action, and not another, like my PC settings) Region Format to Lithuanian. Although it is nonexistent on the menu list! Good news!
    However, the problem is that while I explored my iPod I accidentally checked another region, and there is no "cancel" option. So my region switched to another. And now I am not able to switch it back to Lithuanian again because there is no such selection (reset or restore didn't help).
    Has anybody any suggestions how could I return to my preferred region format (Lithuanian)? Thanks!

    thats interesting. I think the ipod took those settings from your computer/mac.
    anyway, shouldn't there be something near you that has the same region format settings? maybe you can just use something that's exactly the same.
    and btw: some of the regions have arrows next to them which brings you to subregions of that region. maybe you should check that out?
    otherwise ... well ... I think only a restore would bring back the original settings.

  • .pdf with no security settings won't place in InDesign

    A received .pdf file with no security settings will not place in InDesign.  I receive a "This PDF document was saved with security settings which prevents its pages from being placed."  Even when I save it as a new .pdf with no security settings, it won't place.  I'm currently using Acrobat Pro X.  Please advise.  Thanks!

    It could be you need to restore your InDesign preferences. Follow these directions:
    http://pfl.com/trb

  • Problem with SQL connection and a Collection

    hi all,
    I have two problems with sql...
    1. how can I assign the values of a resultset to a collection?
    2. how can I close the sql connection, because when I close the statement and connection error shows me in the resultset
    thanks!

    Hello Pablo,
    RetrivingResults In Collection:
    1)   use getObject method, and assign it to collection.
              Collection c_obj=new ArrayList();
             while(rs.next())
                    c_obj.add(rs.getInt(Project_ID), rs.getString(Project_Name));
    Closing ResultSet
    2)               The close() methos of ResultSet closes the ResultSet object, like bellow
                    ResultSet rs = stmt.executeQuery("SELECT a, b FROM TABLE2");
                    rs.close(); //Closes the result set

  • There is a problem with this connection's security certificate The remote computer cannot be authenticated due to problems with its security certificate. Security certificate problems might indicate an attempt to fool you or intercept any data you send

    Hi,
    I have this Windows 2008 R2 on which I installed remoteapp some years ago.
    Now the certificate expired and I get the message
    "There is a problem with this connection's security certificate
    The remote computer cannot be authenticated due to problems with its security certificate.
    Security certificate problems might indicate an attempt to fool you or intercept any data you send to the remote computer."
    How should I renew the certificate? I already went to certification store and tried to renew certificate with same key but then it says "the request contains nor certificate template information".
    Please advise.
    J.
    J.
    Jan Hoedt

    Does the computer account have Enroll permission to the certificate template?
    From the Server running your CA, run mmc, click File then Add/Remove Snap-in...
    Add Certificate Templates and click OK.
    Find the certificate template, then right click and select properties.  On my CA its call ed RemoteDesktopComputers but might be called something different depending on what what template your certificate is based on.
    On the security tab, click Oblect types, check Computers then OK. Enter the Computername and click OK.  Then give your computer account Enroll permisssion.
    HTH,
    JB

  • Hi all, I'm still having problems with my security questions as they were not the ones I answered. Now I'm confused

    Still having problems with my security questions as they were not the ones I answered and now I'm confused.

    Howdy Paul,
    If you are having an issue with your Apple ID security questions, you can reset them using the steps in this article -
    If you forgot the answers to your Apple ID security questions - Apple Support
    Thanks for using Apple Support Communities.
    Best,
    Brett L 

  • TS1559 please help me...my iphone 4s has a problem with wi-fi settings grayed out or dim

    please help me...my iphone 4s has a problem with wi-fi settings grayed out or dim

    http://support.apple.com/kb/TS1559

  • HT201177 I am having some problems with downloading, possibly settings are incorrect, esp. flashplayer upgrade will not install - i have iMac 8.1 osx v10.5.8 - processor: 3.06 ghz intel core2 duo mem: 2 gb 800 mhz ddr2 sdram

    I am having some problems with downloading, possibly settings are incorrect, esp. flashplayer upgrade will not install - i have iMac 8.1 osx v10.5.8 - processor: 3.06 ghz intel core2 duo mem: 2 gb 800 mhz ddr2 sdram - i am considering making an appt with Apple store nearby since we have a few in vicinity but thought i would give the online support a try.

    The latest version of Adobe FlashPlayer can be obtained from here:
    http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFl ash
    You can check here what version of Flash player you actually have installed:  http://kb2.adobe.com/cps/155/tn_15507.html
    You can check here:  http://www.adobe.com/products/flash/about/  to see which version you should install for your Mac and OS.
    You should first uninstall any previous version of Flash Player, using the uninstaller from here (make sure you use the correct one!):
    http://kb2.adobe.com/cps/909/cpsid_90906.html
    and also that you follow the instructions closely, such as closing ALL applications first before installing. You must also carry out a permission repair after installing anything from Adobe.

  • Hi i have a problem with my security question verify email address

    hi,
    i have a problem with my security question verify email address

    If Manage your Apple ID primary, rescue, alternate, and notification email addresses does not help, you can contact the Apple ID Security site from http://support.apple.com/kb/HT5699 or call the AppleCare support number from http://support.apple.com/kb/HE57 and ask to speak with the Account Security Team.

  • I have problem with the security question i forgot it some body tell me they will show down of the question forgot the answering but nothing show help me plz thanks

    I have problem with the security question i forgot it some body tell me they will show down of the question forgot the answering but nothing show help me plz thanks

    The reset link will only show if you have a rescue email address (which is not the same thing as an alternate email address) set up on your account : http://support.apple.com/kb/HT5312
    If you don't have a rescue email address (you won't be able to add one until you can answer 2 of your questions) then you will need to contact iTunes Support / Apple to get the questions reset.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699
    When they've been reset (and if you don't already have a rescue email address) you can then use the steps half-way down this page to add a rescue email address for potential future use : http://support.apple.com/kb/HT5312

Maybe you are looking for

  • Workflow  - Best practice in B1

    Hi All. Our business has really expanded and we`re starting to think of / work with finding the best workflow. the scenario : we have a warehouse that picks goods, we have a printing department, responsible for printing. we have a production departme

  • How to remove password in Windows Vista?

    Hi! May be somebody can help me... I have a notebook - Satellit L300-11Q. Windows doesn't load correctly, and when I try to run recovery it asks for administrator password... But I never set this password. What should I do?

  • 10 songs will not copy from iTunes to iPod.

    I have been having a problem when syncing my iPod. At the end of the sync, a dialog box appears, saying 'some of the items in the iTunes library, including "song name", were not be copied to the iPod "iPod name" because they could not be found". In t

  • Errors when Installing CS6 10.8

    HI, When I try installing CS6 Master Collection on an 10.8.5 Machine I am receiving the below log full of error messages. I have tried uninstalling and reinstalling the program, Have also tried removing the preferences through the Adobe cc cleaner. I

  • Disclaimer page for Muse site

    Can anyone explain how I can create a disclaimer page for my Muse site?